CVE-2026-10520

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:standalone_sentry:10.7.0:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección de comandos del sistema operativo en Ivanti Sentry anterior a las versiones R10.5.2, R10.6.2 y R10.7.1 permite a un usuario remoto no autenticado lograr ejecución remota de código a nivel de root.

12 Jun 2026, 12:42

Type Values Removed Values Added
First Time Ivanti standalone Sentry
Ivanti
CPE cpe:2.3:a:ivanti:standalone_sentry:10.7.0:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*
References () https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US - () https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US - Patch, Vendor Advisory
References () https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 - () https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 - Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520 - US Government Resource

11 Jun 2026, 20:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520 -

11 Jun 2026, 14:16

Type Values Removed Values Added
References
  • () https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 -

09 Jun 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 16:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-10520

Mitre link : CVE-2026-10520

CVE.ORG link : CVE-2026-10520


JSON object : View

Products Affected

ivanti

  • standalone_sentry
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')