Arbitrary Code Execution Vulnerability in Sentry Error Tracking Tool
CVE-2026-83803

7.7HIGH

Key Information:

Vendor

Getsentry

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-83803?

Sentry, a widely used error tracking and performance monitoring tool, has a vulnerability that affects versions from 23.11.0 to 26.7.0. This issue arises when the relocation feature is enabled. Specifically, it involves unsafe deserialization of a legacy database field, allowing an authenticated user to craft a relocation archive that could trigger arbitrary code execution in the import worker process. By default, this feature is disabled in self-hosted installations, rendering them unaffected. The issue has been resolved in version 26.7.0, and users of earlier versions are advised to upgrade to mitigate potential risks.

Affected Version(s)

sentry >= 23.11.0, < 26.7.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.