Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Functional Software
Functional Software sentry Seer |
|
| Vendors & Products |
Functional Software
Functional Software sentry Seer |
Fri, 18 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 CWE-74 CWE-913 |
|
| Metrics |
cvssV3_1
|
Fri, 18 Sep 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-94 |
Wed, 16 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure. | |
| Title | Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-09-18T13:40:22.164Z
Reserved: 2026-09-14T15:22:28.291Z
Link: CVE-2026-90999
Updated: 2026-09-16T16:08:56.590Z
Status : Deferred
Published: 2026-09-16T16:17:21.817
Modified: 2026-09-18T17:49:08.457
Link: CVE-2026-90999
No data.
OpenCVE Enrichment
Updated: 2026-09-20T05:15:16Z