Arbitrary Code Execution Vulnerability in Sentry Error Tracking Tool
CVE-2026-83803
7.7HIGH
What is CVE-2026-83803?
Sentry, a widely used error tracking and performance monitoring tool, has a vulnerability that affects versions from 23.11.0 to 26.7.0. This issue arises when the relocation feature is enabled. Specifically, it involves unsafe deserialization of a legacy database field, allowing an authenticated user to craft a relocation archive that could trigger arbitrary code execution in the import worker process. By default, this feature is disabled in self-hosted installations, rendering them unaffected. The issue has been resolved in version 26.7.0, and users of earlier versions are advised to upgrade to mitigate potential risks.
Affected Version(s)
sentry >= 23.11.0, < 26.7.0
