{"id":"CVE-2026-90999","published":"2026-09-16T16:17:21.817","lastModified":"2026-09-18T17:49:08.457","description":"Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-20","CWE-74","CWE-94","CWE-116","CWE-913"],"vendors":[],"products":[],"references":[{"url":"https://kb.cert.org/vuls/id/212479","tags":[]},{"url":"https://www.kb.cert.org/vuls/id/212479","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to execute arbitrary code via fabricated telemetry events, bypassing authentication and privilege controls.","exploitability":"Exploitation is relatively easy given the lack of authentication requirements, but requires access to Sentry Seer's event submission interface.","blast_radius":"If exploited, this could lead to full control over the victim’s privileged automation environment, potentially leading to data exfiltration and system compromise.","remediation":"Implement strict input validation and sanitization for telemetry events to prevent code injection.","tags":["rce","auth-bypass","telemetry","automation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-23T08:46:17.284Z"}}