CVE-2026-10520

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:standalone_sentry:10.7.0:*:*:*:*:*:*:*

History

12 Jun 2026, 12:42

Type Values Removed Values Added
References () https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US - () https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US - Patch, Vendor Advisory
References () https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 - () https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 - Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520 - US Government Resource
First Time Ivanti standalone Sentry
Ivanti
CPE cpe:2.3:a:ivanti:standalone_sentry:10.7.0:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*

11 Jun 2026, 20:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520 -

11 Jun 2026, 14:16

Type Values Removed Values Added
References
  • () https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 -

09 Jun 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 16:16

Updated : 2026-06-12 12:42


NVD link : CVE-2026-10520

Mitre link : CVE-2026-10520

CVE.ORG link : CVE-2026-10520


JSON object : View

Products Affected

ivanti

  • standalone_sentry
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')