보안 뉴스 · 취약점
2026-008: Critical vulnerabilities in Ivanti Sentry
출처: CERT-EU · © Cybersecurity Service for the Union institutions, bodies, offices and agencies (CERT-EU). · CC BY 4.0
문서 서식과 링크를 FineTS 화면에 맞게 정리했습니다. 이미지·첨부파일은 공식 원문에서 확인하세요.
| 취약점 | 설명 | 조치사항 |
|---|---|---|
| CVE-2026-10520 |
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution |
조치사항 확인이 필요합니다. |
| CVE-2026-10523 |
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access |
조치사항 확인이 필요합니다. |
한국어 버튼을 눌러 번역을 요청할 수 있습니다.
On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
History:
- 10/06/2026 --- v1.0 -- Initial publication
Summary
On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
Technical Details
The vulnerability CVE-2026-10520, with a CVSS score of 10, is an OS Command Injection vulnerability in Ivanti Sentry which allows a remote unauthenticated user to achieve root-level remote code execution[2].
The vulnerability CVE-2026-10523, with a CVSS score of 9.9, is an Authentication Bypass vulnerability in Ivanti Sentry which allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access.
Affected Products
The following versions of Ivanti Sentry are affected:
- 10.5.1 and prior.
- 10.6.1 and prior.
- 10.7.0 and prior.
Recommendations
CERT-EU recommends following the vendor's guidance to update their appliance to one of the fixed versions[1].
References
[1] https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523