OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-90999

CRITICAL · CVSS 9.8 EPSS 0.67%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Sentry Seer is susceptible to a multi-stage trust-boundary violation, enabling unauthenticated attackers to execute malicious code within a privileged automation environment by submitting forged telemetry events. This vulnerability poses a significant risk as it allows external actors to manipulate the system without needing access to the victim's Sentry account or infrastructure. Organizations utilizing Sentry Seer should prioritize addressing this issue to safeguard their automation environments from potential exploitation.

CVE
CVE-2026-90999
Severity
CRITICAL
CVSS
9.8
EPSS
0.67%

Original NVD Description

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.