CVE-2026-10523
📛 CVE Title
CVE-2026-10523
Description
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
Overview
- State
- PUBLISHED
- Assigner (CNA)
- ivanti
- CVSS severity
- CRITICAL
- CVSS score
- 9.9 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H- Effective score
- 9.9 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-288 - Reserved
- 2026-06-01
- Published
- 2026-06-09 14:16 UTC
- Last updated
- 2026-06-10 03:58 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/10xxx/CVE-2026-10523.json
- Linked Threat
- CVE-2026-10523 — CVE-2026-10523
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- EPSS score
- 0.0481 (probability of exploitation in next 30 days)
- EPSS percentile
- 90.83% vs all CVEs — higher = more likely to be exploited, as of 2026-06-18
NVD / KEV / EPSS data refreshed 2026-06-19 11:35 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-35441 - Assigner
- ivanti
- Published
- Jun 9, 2026, 2:16:41 PM
- Updated
- Jun 10, 2026, 3:58:55 AM
- EUVD base score (CVSS 3.1)
-
9.9 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - EUVD-reported EPSS
- 51.8700
- Vendors
- Ivanti
- Products
-
sentry (patch: R10.6.2)sentry (patch: R10.5.2)sentry (patch: R10.7.1)
- Aliases
-
GHSA-8fc8-rw5j-9rcq
ENISA description: An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| ivanti | Sentry |
R10.5.2 (unaffected),
R10.6.2 (unaffected),
R10.7.1 (unaffected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
MITRE references (1) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:beazley.security
Executive Summary On June 9th, Ivanti published two advisories concerning four vulnerabilities (tracked as CVE - 2026 -6973, CVE - 2026 -10727, CVE - 2026 -10520, CVE-2026-10523 ) in their Endpoint Manager Mobile (EPMM) and Ivanti Sentry products. The vulnerabilities range from authentication bypass and control plane modification to complete remote code execution (RCE) across the product lines. Detailed ...
2026-06-19 02:16 UTC -
web:cvefeed.io
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
2026-06-19 02:16 UTC -
web:cvetodo.com
To remediate CVE-2026-10523 : Check ivanti's security advisories for official patches and updates. Update Sentry to the latest patched version. Review the references section below for vendor advisories and mitigation guidance.
2026-06-19 02:16 UTC -
web:hub.ivanti.com
What is the risk to customers for CVE - 2026 -10520 & CVE-2026-10523 ? While the CVSS score for CVE - 2026 -10520 & CVE-2026-10523 is critical, the risk is decreased significantly based on deployment and configuration. For EPMM-managed Sentry appliances, the vulnerable APIs are protected by mTLS after management.
2026-06-19 02:16 UTC -
web:kudelskisecurity.com
CVE-2026-10523 - Authentication Bypass An authentication bypass vulnerability allows remote unauthenticated attackers to create arbitrary administrative accounts and obtain full administrative privileges over the appliance, potentially facilitating further compromise of connected enterprise environments. Mitigation
2026-06-19 02:16 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-06-19 02:16 UTC -
web:securityboulevard.com
The second flaw, tracked as CVE-2026-10523 , is a critical authentication bypass that can be exploited remotely by unauthenticated attackers to create rogue administrative accounts and gain full administrative access. Ivanti patched both issues with the release of Sentry versions R10.5.2, R10.6.2, and R10.7.1.
2026-06-19 02:16 UTC -
web:www.csoonline.com
Two vulnerabilities in the secure mobile gateway appliance allow unauthenticated attackers to bypass authentication and execute OS commands as root.
2026-06-19 02:16 UTC -
web:www.esentire.com
THE THREAT On June 9th, 2026 , Ivanti disclosed two critical vulnerabilities affecting its Sentry secure mobile gateway solution. These vulnerabilities are identified as CVE - 2026 -10520 (CVSS: 10.0) and CVE-2026-10523 (CVSS: 9.9), both of which could allow remote, unauthenticated attackers to fully compromise affected systems.
2026-06-19 02:16 UTC -
web:www.rapid7.com
For the latest mitigation guidance, please refer to the vendor's security advisory. Rapid7 customers Exposure Command, InsightVM, and Nexpose Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE - 2026 -10520 and CVE-2026-10523 with unauthenticated vulnerability checks available in the June 11 content release. Updates
2026-06-19 02:16 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-10523.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-10523",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-09T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-10T03:58:55.720Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "Sentry",
"vendor": "ivanti",
"versions": [
{
"status": "unaffected",
"version": "R10.5.2"
},
{
"status": "unaffected",
"version": "R10.6.2"
},
{
"status": "unaffected",
"version": "R10.7.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access "
}
],
"value": "An Authentication Bypass vulnerability (CWE-288)\u00a0in Ivanti\u00a0Sentry before the\u00a0R10.5.2, R10.6.2 and R10.7.1\u00a0versions\u00a0allows\u00a0a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access"
}
],
"impacts": [
{
"capecId": "CAPEC-115",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-115 Authentication Bypass"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-288",
"description": "CWE-288 Authentication bypass using an alternate path or channel",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-06-09T14:17:40.240Z",
"orgId": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
"shortName": "ivanti"
},
"references": [
{
"url": "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
"assignerShortName": "ivanti",
"cveId": "CVE-2026-10523",
"datePublished": "2026-06-09T14:16:41.255Z",
"dateReserved": "2026-06-01T08:57:47.470Z",
"dateUpdated": "2026-06-10T03:58:55.720Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}