Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability in Sentry's GroupEventJsonView endpoint. Version 26.1.0 patches the issue.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getsentry
Getsentry sentry |
|
| Vendors & Products |
Getsentry
Getsentry sentry |
Tue, 17 Mar 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability in Sentry's GroupEventJsonView endpoint. Version 26.1.0 patches the issue. | |
| Title | Sentry allows unauthorized access to event data across organizational boundaries | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-18T20:17:22.669Z
Reserved: 2026-02-09T17:41:55.860Z
Link: CVE-2026-26004
No data.
Status : Awaiting Analysis
Published: 2026-03-18T00:16:18.943
Modified: 2026-03-18T14:52:44.227
Link: CVE-2026-26004
No data.
OpenCVE Enrichment
Updated: 2026-03-18T10:42:33Z
Weaknesses