Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 CWE-74 CWE-913 |
|
| Metrics |
cvssV3_1
|
Fri, 18 Sep 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-94 |
Wed, 16 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure. | |
| Title | Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-09-18T13:40:22.164Z
Reserved: 2026-09-14T15:22:28.291Z
Link: CVE-2026-90999
Updated: 2026-09-16T16:08:56.590Z
Status : Received
Published: 2026-09-16T16:17:21.817
Modified: 2026-09-18T14:19:02.747
Link: CVE-2026-90999
No data.
OpenCVE Enrichment
Updated: 2026-09-18T05:00:04Z
-
CWE-116
Improper Encoding or Escaping of Output
-
CWE-20
Improper Input Validation
-
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
-
CWE-913
Improper Control of Dynamically-Managed Code Resources
-
CWE-94
Improper Control of Generation of Code ('Code Injection')