Threat Insight

Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523)

Ivanti has released a security advisory addressing two critical vulnerabilities in Ivanti Sentry. These vulnerabilities could allow unauthenticated attackers to execute arbitrary commands or gain full administrative access to affected systems.

  • Insight

The cause of the flaw has at the time of writing not been shared by the vendor.

CVE-2026-10520: An OS command injection vulnerability that allows a remote unauthenticated attacker to execute arbitrary commands with root privileges on affected devices.

CVE-2026-10523: An authentication bypass vulnerability that allows a remote unauthenticated attacker to create arbitrary administrative accounts and gain full administrative access A proof-of-concept exploit is available to the public[2].

CVE

CVE-2026-10520

CVE-2026-10523

Affected Products

Ivanti Sentry versions prior to R10.5.2, R10.6.2 and R10.7.1[1].

Exploitation

At the time of disclosure, Ivanti stated that it was not aware of any customers being exploited by these vulnerabilities[1].

Recommended Actions

Truesec recommends that if you are effected, upgrade Ivanti Sentry to versions 10.5.2, 10.6.2 and 10.7.1 as soon as possible.

The versions are found here[1]:

10.5.2:
New Sentry Instance: https://support.mobileiron.com/mi/sentry/10.5.2-3/sentry-mobileiron-10.5.2-3.iso
Updating existing Sentry appliance: https://support.mobileiron.com/mi/sentry/10.5.2-3/

10.6.2:
New Sentry Instance: https://support.mobileiron.com/mi/sentry/10.6.2-4/sentry-mobileiron-10.6.2-4.iso
Updating existing Sentry appliance: https://support.mobileiron.com/mi/sentry/10.6.2-4/

10.7.1:
New Sentry Instance: https://support.mobileiron.com/mi/sentry/10.7.1-3/sentry-mobileiron-10.7.1-3.iso
Updating existing Sentry appliance: https://support.mobileiron.com/mi/sentry/10.7.1-3/

References

[1] https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US

[2] https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights