rootpwn

Advisories

Dual Critical Flaws in Ivanti Sentry Enable Unauthenticated RCE and Admin Account Creation

CERT‑EU has exposed two zero‑day weaknesses in Ivanti Sentry appliances. CVE‑2026‑10520 is an OS command injection that can be leveraged for root‑level remote code execution, while CVE‑2026‑10523 allows attackers to bypass authentication and create arbitrary administrative accounts. All Sentry releases up to 10.7.0 are affected. Immediate patching is required to avoid exploitation.

On June 9 2026, CERT‑EU released a security advisory detailing two critical vulnerabilities in Ivanti Sentry appliances that grant attackers unauthenticated remote code execution and full administrative control.

What the Vulnerabilities Do

  • CVE‑2026‑10520 – OS command injection (CVSS 10.0) that lets a remote attacker run arbitrary commands with root privileges.
  • CVE‑2026‑10523 – Authentication bypass (CVSS 9.9) enabling creation of new administrative accounts and complete device takeover.

Affected Versions

  • Ivanti Sentry 10.5.1 and earlier
  • Ivanti Sentry 10.6.1 and earlier
  • Ivanti Sentry 10.7.0 and earlier

Mitigation

Update to a patched version immediately. No work‑arounds are available; the only safe path is to apply the vendor’s fix.

Takeaway

These flaws expose every Sentry appliance to a full compromise without any authentication. If you run any of the affected versions, patching should be your top priority.

Ivanti Sentry RCE Auth Bypass CERT‑EU

← All news