# Ivanti Sentry Auth Bypass Grants Admin Access

Published: 2026-09-09 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/de6b200e-3ea7-5b61-a7be-f117d1d6a077/ivanti-sentry-auth-bypass-grants-admin-access

> An authentication bypass in Ivanti Sentry lets unauthenticated remote attackers gain administrative access; patches available.

NCSC-NL published an advisory for an authentication bypass vulnerability (CVE-2026-83527, CVSSv3 8.1) affecting Ivanti Sentry versions prior to R10.8.2, R10.7.3, and R10.6.4. The flaw is classified as authentication bypass using an alternate path or channel, allowing unauthenticated remote attackers to obtain administrative access to affected systems, potentially resulting in full unauthorized control over administrative functions.

Ivanti has released updated versions that remediate the vulnerability. No evidence of active in-the-wild exploitation is mentioned in the advisory. Defenders running Ivanti Sentry should prioritize patching to the fixed releases (R10.8.2, R10.7.3, R10.6.4 or later) and review administrative access logs for anomalous or unauthorized administrative activity as a precautionary detection measure, given the criticality of admin-level compromise on this platform.

## Mentioned in this report

- Vulnerabilities: CVE-2026-83527

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0357.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/de6b200e-3ea7-5b61-a7be-f117d1d6a077/ivanti-sentry-auth-bypass-grants-admin-access.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
