CVE-2026-90999
Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
Description
Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.
In plain language
AI Act nowSentry Seer can let an outsider send fake data that runs harmful commands in a high-permission automation system, so businesses using it for privileged automated operations should act now.
Unauthenticated network-based arbitrary code execution arises when attacker-controlled Sentry telemetry is interpreted as instructions by Sentry Seer agents operating in a privileged environment.
What to do now
- Check whether your organization uses Sentry Seer for automated agent operations with high system permissions.
- Temporarily stop or isolate any Sentry Seer agents that accept data from the internet and can run privileged commands.
- No fixed version has been published; ask the vendor for a security update and deploy it as soon as one is available.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-90999 and every CVE in our database. Create a free account — no credit card required.
Create Free Account