Junglewise Threat Intelligence

CVE-2026-10520: Ivanti Sentry OS command injection allows remote code execution

CVE-2026-10520 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-06-09

Technologies: Ivanti Sentry. Vendors: Ivanti.

Executive brief

Ivanti Sentry, a gateway used to manage and secure traffic between mobile devices and corporate servers, contains a critical security flaw. An attacker can exploit this vulnerability over the internet without needing any login credentials to take full control of the system. This could lead to a complete compromise of the appliance, allowing unauthorized access to sensitive corporate data or serving as a foothold for further attacks on the internal network.

Technical details

An OS command injection vulnerability (CWE-78) exists in Ivanti Sentry (formerly MobileIron Sentry) due to improper neutralization of special elements in user-supplied input. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to an exposed Sentry interface, leading to remote code execution with root privileges. The vulnerability is particularly impactful when the appliance is in an unmanaged state with externally reachable endpoints. Exploitation is mitigated if mTLS is used with EPMM or if HTTPS access is restricted through Neurons for MDM. Ivanti has released patches in versions R10.5.2, R10.6.2, and R10.7.1.

Affected products

  • Ivanti Sentry (formerly MobileIron Sentry) Before R10.5.2, R10.6.2, and R10.7.1

Timeline

  • 2026-06-09: advisory: Initial advisory published by Ivanti
  • 2026-06-11: disclosed: CVE record published to NVD
  • 2026-06-11: exploited: Reported as being exploited in the wild

Related threats