An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ivanti
Ivanti sentry |
|
| Vendors & Products |
Ivanti
Ivanti sentry |
Tue, 09 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OS Command Injection in Ivanti Sentry Allowing Root-Level Remote Code Execution |
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ivanti
Published: 2026-06-09T14:10:21.581Z
Updated: 2026-06-09T15:42:24.876Z
Reserved: 2026-06-01T08:47:35.793Z
Link: CVE-2026-10520
Updated: 2026-06-09T15:42:20.215Z
Status : Received
Published: 2026-06-09T16:16:35.700
Modified: 2026-06-09T16:16:35.700
Link: CVE-2026-10520
No data.