Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.7
CVE-2026-83803: Sentry relocation import can run attacker code
CVE-2026-83803 · published 19 days ago
Summary
Self-hosted Sentry versions 23.11.0 through 26.7.0 allow a logged‑in user to create a specially crafted relocation archive that, when imported, can cause the system to execute any code it wants. The risk only applies when the relocation feature is turned on, which is off by default. Upgrade to version 26.7.0 or later, or keep the relocation feature disabled, to eliminate the threat.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| getsentry | sentry | >= 23.11.0, < 26.7.0 |
Original advisory text
Sentry: Unsafe pickle deserialization in Relocation Feature
Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the relocation feature enabled unsafely deserialize a legacy database field while importing a user-supplied relocation archive. An authenticated user can craft an archive that causes arbitrary code execution in the import worker process. Self-hosted installations using the default configuration are not affected because the relocation feature is disabled by default. This issue is fixed in version 26.7.0.
References
- https://github.com/getsentry/sentry/security/advisories/GHSA-xm86-7c47-gjm4
- https://github.com/getsentry/sentry/pull/119622
- https://github.com/getsentry/sentry/commit/d7fd44193c282102f9fcd2c73973820f3d10a...
- https://github.com/getsentry/sentry/releases/tag/26.7.0
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83803... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-83803 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
7.7
High
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published22 Sep 2026
Updated11 Oct 2026
First seen22 Sep 2026
Track software like this
Free during beta