EXPOSURES › CVE-2026-10523
CVE-2026-10523
CRITICAL
DETAIL
SourceNVD · cve
Published2026-06-09
CVSS9.9
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-10523 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
AFFECTED FEDRAMP PRODUCTS · 2
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |