VDB

CVE-2026-10520

CVE-2026-10520 PUBLISHED KEV CVSS 10 CRITICAL

CVE-2026-10520 is an OS command injection vulnerability with a maximum CVSS score of 10.0 that can be exploited remotely without authentication to execute arbitrary code with root privileges. CVE-2026-10523 is an authentication bypass vulnerability (CVSS:3.1 9.9) that allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access. The flaw enables attackers to circumvent normal authentication mechanisms, fundamentally undermining the security model of the system.

EPSS 99.89% · 100.0th percentile

Risk Scores

CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
99.89%
100.0th percentile

Affected Products

VendorProductVersions
IvantiIvanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions

Timeline

  • CVE Published
  • Feb 20, 2022 CrowdSec Sighting
  • Feb 28, 2022 CrowdSec Sighting
  • Mar 4, 2022 CrowdSec Sighting
  • Mar 7, 2022 CrowdSec Sighting
  • Apr 18, 2022 CrowdSec Sighting
  • May 13, 2022 CrowdSec Sighting
  • May 16, 2022 CrowdSec Sighting
  • May 19, 2022 CrowdSec Sighting
  • May 20, 2022 CrowdSec Sighting
  • May 21, 2022 CrowdSec Sighting
  • May 31, 2022 CrowdSec Sighting
Open in Interactive Console →
$ Console Community · 100/wk Open console ›