Executive brief
A critical vulnerability in Sentry's SAML Single Sign-On (SSO) implementation allows an attacker to take over any user account. By using a malicious identity provider on a multi-organization instance, an attacker can link their identity to a victim's account if they know the victim's email address. This could lead to full account compromise and unauthorized access to sensitive error tracking and performance data.
Technical details
An improper authentication vulnerability (CWE-287) exists in Sentry's SAML SSO process. The flaw allows an attacker with permissions to modify SSO settings for one organization on a multi-tenant Sentry instance to use a malicious SAML Identity Provider to link to and take over accounts in other organizations. Exploitation requires the attacker to know the victim's email address and for the instance to have SENTRY_SINGLE_ORGANIZATION set to False. The vulnerability is mitigated if individual users have two-factor authentication (2FA) enabled. A fix has been deployed to Sentry SaaS and is available for self-hosted users in version 26.2.0.
Affected products
- Sentry Sentry >= 21.12.0, < 26.2.0
Timeline
- 2026-02-18: patched: Fix deployed to Sentry SaaS and version 26.2.0 released.
- 2026-02-21: advisory: NVD publication date.
- 2026-04-17: disclosed: GitHub Advisory published.
References
- https://api.github.com/users/Muhammad-Qasim-Munir
- https://github.com/Muhammad-Qasim-Munir
- https://api.github.com/users/Muhammad-Qasim-Munir/gists%7B/gist_id%7D
- https://api.github.com/users/Muhammad-Qasim-Munir/repos
- https://avatars.githubusercontent.com/u/49307757?v=4
- https://api.github.com/users/Muhammad-Qasim-Munir/events%7B/privacy%7D