CVE-2026-10520
CVE-2026-10520
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
ivanti · Sentrypublic PoCs found — 5
cve_referencegithub.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523★ 13githubgithub.com/0xBlackash/CVE-2026-10520★ 4githubgithub.com/ogenich/CVE-2026-10520★ 2githubgithub.com/HORKimhab/CVE-2026-10520-10523★ 0githubgithub.com/error-inside/CVE-2026-10520★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →