CVE-2026-10520
CRITICAL
10,0
Source: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,4270
Percentile
1,0th
Updated
EPSS Score Trend (Last 5 Days)
78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
StableCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Non-Repudiation
Potential Impacts:
Execute Unauthorized Code Or Commands
Dos: Crash, Exit, Or Restart
Read Files Or Directories
Modify Files Or Directories
Read Application Data
Modify Application Data
Hide Activities
Applicable Platforms
Technologies:
Not Technology-Specific, AI/ML, Web Server
Application
Standalone Sentry by Ivanti
CPE Identifier
View Detailed Analysis
cpe:2.3:a:ivanti:standalone_sentry:10.7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Standalone Sentry by Ivanti
Version Range Affected
To
10.5.2
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Standalone Sentry by Ivanti
Version Range Affected
From
10.6.0
(inclusive)
To
10.6.2
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:ivanti:standalone_sentry:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-…
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026…
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520…