EXPOSURES › CVE-2026-10520
CVE-2026-10520
HIGH ⌖ ON CISA KEV · EXPLOITEDIvanti Sentry allows remote unauthenticated root access via command injection when appliances are unmanaged and externally reachable.
This OS command injection flaw enables remote code execution on unmanaged Sentry appliances, bypassing mTLS and restricted HTTPS controls. DIB orgs must ensure all Sentry devices are managed and patched immediately to prevent unauthorized root access and potential data exfiltration.
Shame score — A critical unauthenticated RCE vulnerability in a widely deployed MDM product that can be exploited when devices are left unmanaged.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |