CVE-2026-26004

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
18/03/2026
Last modified:
23/03/2026

Description

Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability in Sentry's GroupEventJsonView endpoint. Version 26.1.0 patches the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sentry:sentry:*:*:*:*:*:*:*:* 26.1.0 (excluding)