VDB
CVE-2026-10520
CVE-2026-10520
PUBLISHED
KEV
CVSS 10 CRITICAL
CVE-2026-10520 is an OS command injection vulnerability with a maximum CVSS score of 10.0 that can be exploited remotely without authentication to execute arbitrary code with root privileges. CVE-2026-10523 is an authentication bypass vulnerability (CVSS:3.1 9.9) that allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access. The flaw enables attackers to circumvent normal authentication mechanisms, fundamentally undermining the security model of the system.
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions |
Exploit Intelligence
- CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry (github-poc-repo)
- CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry (github-poc-repo)
- CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry (github-poc-repo)
- CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry (github-poc-repo)
- CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry (github-poc-repo)
- CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry (github-poc-repo)
- CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry (github-poc-repo)
- CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry (github-poc-repo)
- CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry (github-poc-repo)
- CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry (github-poc-repo)
…and 125 more exploits
Timeline
- CVE Published
- May 16, 2022 CrowdSec Sighting
- Apr 5, 2023 CrowdSec Sighting
- Sep 15, 2025 CrowdSec Sighting
- Jun 11, 2026 CISA KEV Added
- Jun 11, 2026 PoC Published
- Jun 11, 2026 Coalition ESS Score
- Jun 11, 2026 Security Advisory
- Jun 14, 2026 CrowdSec Sighting
References
- https://ccb.belgium.be/advisories/warning-critical-root-level-remote-code-execution-and-authentication-bypass advisory
- https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US vendor
- https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/ technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-10520 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-10523 technical
- https://vuldb.com/cve/CVE-2026-10523 technical
- https://www.bleepingcomputer.com/news/security/new-max-severity-ivanti-sentry-flaw-allows-code-execution-as-root/ technical