CVE-2026-26004

Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability in Sentry's GroupEventJsonView endpoint. Version 26.1.0 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sentry:sentry:*:*:*:*:*:*:*:*

History

23 Mar 2026, 18:12

Type Values Removed Values Added
References () https://github.com/getsentry/sentry/commit/45bc78fd57514a04eb62e73dd1eeb3ca2d723997 - () https://github.com/getsentry/sentry/commit/45bc78fd57514a04eb62e73dd1eeb3ca2d723997 - Patch
References () https://github.com/getsentry/sentry/pull/105601 - () https://github.com/getsentry/sentry/pull/105601 - Issue Tracking, Patch
References () https://securitylab.github.com/advisories/GHSL-2025-130_Sentry/ - () https://securitylab.github.com/advisories/GHSL-2025-130_Sentry/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:sentry:sentry:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Sentry sentry
Sentry

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Sentry es una herramienta de seguimiento de errores y monitoreo de rendimiento orientada a desarrolladores. Las versiones anteriores a la 26.1.0 tienen una vulnerabilidad de Referencia Directa Insegura a Objeto (IDOR) interorganizacional en el endpoint GroupEventJsonView de Sentry. La versión 26.1.0 corrige el problema.

18 Mar 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-18 00:16

Updated : 2026-03-23 18:12


NVD link : CVE-2026-26004

Mitre link : CVE-2026-26004

CVE.ORG link : CVE-2026-26004


JSON object : View

Products Affected

sentry

  • sentry
CWE
CWE-639

Authorization Bypass Through User-Controlled Key