Unauthenticated Authentication Bypass in Ivanti Sentry Grants Full Admin Access
CVSS 3.1
9.8critical
EPSS
52%p99
Published
()
Modified
AI analysis
CVE-2026-10523 is an authentication bypass (CWE-288) in Ivanti Sentry, the gateway component formerly known as MobileIron Sentry, affecting standalone deployments before the R10.5.2, R10.6.2, and R10.7.1 releases. A remote, unauthenticated attacker can exploit it over the network with no credentials, no user interaction, and no special conditions, creating arbitrary administrative accounts on the affected gateway. The attacker thereby obtains full administrative control of Sentry, which in most deployments sits at the network edge handling mobile-device (MDM/UEM) traffic for organizations using Ivanti's mobility management stack. Any organization running an affected standalone Sentry version is exposed, with internet-facing instances at greatest risk. Exploitation has not yet been confirmed in the wild (no public PoC, not in CISA KEV), but the high EPSS score of 51.9% (99th percentile) indicates a strong likelihood of exploitation within the next 30 days.
What to do: Upgrade standalone Ivanti Sentry to R10.5.2, R10.6.2, or R10.7.1 depending on your current release branch. Until patched, restrict network exposure of Sentry (especially direct internet access) and review the administrative account list for unexpected admin accounts created without authorization. Given the critical severity and high EPSS, prioritize patching internet-facing instances first.
Affected
Ivanti Sentry (standalone)
All standalone Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1 (i.e., each release branch R10.5.x, R10.6.x, and R10.7.x before its respective fixed relea
Estimated exposure
moderate≈1,000–10,000 internet-exposed Sentry deployments (estimate) — Ivanti Sentry is an enterprise-only MDM gateway deployed once per organization rather than mass-market software, and prior public internet scans of exposed Ivanti/MobileIron Sentry instances have found on the order of a few thousand…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
Ivanti patched Sentry: pre-auth OS command injection CVE-2026-10520 (CVSS 10) enables unauthenticated root RCE, and auth bypass CVE-2026-10523 (CVSS 9.9).
On 9 June 2026 Ivanti released an advisory fixing two critical flaws in Ivanti Sentry versions 10.5.1 and prior, 10.6.1 and prior, and 10.7.0 and prior. CVE-2026-10520 (CVSS 10.0) is an OS command injection allowing a remote unauthenticated attacker to achieve root-level RCE. CVE-2026-10523 (CVSS 9.9) is an authentication bypass letting an unauthenticated attacker create arbitrary administrative accounts and obtain full admin access. CERT-EU recommends updating appliances to fixed versions following Ivanti's guidance.