Executive brief
Ivanti Sentry is an IT service management platform used by organizations to manage IT operations and security. This vulnerability allows an unauthenticated remote attacker to gain administrative access to the system without proper credentials, potentially enabling full compromise of the platform and exposure of sensitive IT infrastructure data.
Technical details
An authentication bypass vulnerability exists in Ivanti Sentry prior to versions R10.8.2, R10.7.3, and R10.6.4. The flaw allows a remote, unauthenticated attacker to bypass authentication mechanisms and obtain administrative-level privileges. The vulnerability is network-reachable and requires no prior authentication or user interaction. An attacker exploiting this can gain full administrative control of the Sentry platform, potentially accessing sensitive IT management data and configurations. Patches are available in R10.8.2, R10.7.3, and R10.6.4 or later versions.
Affected products
- Ivanti Sentry before R10.8.2, R10.7.3, and R10.6.4
Timeline
- 2026-09-08: disclosed