Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.7

CVE-2026-83803: Sentry relocation import can run attacker code

CVE-2026-83803 · published 19 days ago
Summary

Self-hosted Sentry versions 23.11.0 through 26.7.0 allow a logged‑in user to create a specially crafted relocation archive that, when imported, can cause the system to execute any code it wants. The risk only applies when the relocation feature is turned on, which is off by default. Upgrade to version 26.7.0 or later, or keep the relocation feature disabled, to eliminate the threat.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
getsentry sentry >= 23.11.0, < 26.7.0
Original advisory text
Sentry: Unsafe pickle deserialization in Relocation Feature
Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the relocation feature enabled unsafely deserialize a legacy database field while importing a user-supplied relocation archive. An authenticated user can craft an archive that causes arbitrary code execution in the import worker process. Self-hosted installations using the default configuration are not affected because the relocation feature is disabled by default. This issue is fixed in version 26.7.0.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
7.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published22 Sep 2026
Updated11 Oct 2026
First seen22 Sep 2026
Sources
CVE-2026-83803 · MITRE
Track software like this
Free during beta