CVE-2026-90999

Summary

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.

Affected Software

VendorProductVersion RangeStatus
Functional Software, Inc.Sentry SeerWeb siteaffected

Weaknesses

  • CWE-20 Improper Input Validation
  • CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
  • CWE-116 Improper Encoding or Escaping of Output
  • CWE-94 Improper Control of Generation of Code ('Code Injection')
  • CWE-913 Improper Control of Dynamically-Managed Code Resources

ADP Enrichment

CVE Program Container

Additional References

References