CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-10520

KEV Critical · CVSS 10.0

Ivanti Sentry — OS Command Injection RCE

CVSS
10.0
nvd
EPSS
KEV
Listed
2026-06-11
Class
other
CWE-78

Description

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Search profile — drives PoC discovery

Symbols CVE-2026-10520CVE-2026-10523watchTowr-vs-Ivanti-Sentry-RCEwatchtowrlabsroot-level RCEunauthenticated
Keywords CVE-2026-10520CVE-2026-10523Ivanti Sentry RCEIvanti Sentry OS command injectionIvanti Sentry unauthenticated RCEwatchTowr Ivanti SentryIvanti Sentry R10.5.2 R10.6.2 R10.7.1Sentry root RCE PoCwatchtowrlabs Sentry exploit
Versions: before R10.5.2, R10.6.2, R10.7.1

Ranked PoCs (5) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-12T18:00:30.000Z · profiled 2026-06-16T18:19:23.017Z