Ivanti Sentry Auth Bypass Grants Admin Access
An authentication bypass in Ivanti Sentry lets unauthenticated remote attackers gain administrative access; patches available.
NCSC-NL published an advisory for an authentication bypass vulnerability (CVE-2026-83527, CVSSv3 8.1) affecting Ivanti Sentry versions prior to R10.8.2, R10.7.3, and R10.6.4. The flaw is classified as authentication bypass using an alternate path or channel, allowing unauthenticated remote attackers to obtain administrative access to affected systems, potentially resulting in full unauthorized control over administrative functions.
Ivanti has released updated versions that remediate the vulnerability. No evidence of active in-the-wild exploitation is mentioned in the advisory. Defenders running Ivanti Sentry should prioritize patching to the fixed releases (R10.8.2, R10.7.3, R10.6.4 or later) and review administrative access logs for anomalous or unauthorized administrative activity as a precautionary detection measure, given the criticality of admin-level compromise on this platform.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0357.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free