VDB

CVE-2026-90999

CVE-2026-90999 PUBLISHED

Reported by certcc · Published September 16, 2026

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.

Affected Products

VendorProductVersions
Functional Software, Inc.Sentry SeerWeb site
Functional Software, Inc.Sentry SeerWeb site

Timeline

  • Sep 16, 2026 Coalition ESS Score
  • Sep 16, 2026 CVE Published
  • Sep 16, 2026 CVE Updated
  • Sep 17, 2026 EPSS Score
  • Sep 17, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›