{"id":"CVE-2026-90999","published":"2026-09-16T16:17:21.817","lastModified":"2026-09-18T17:49:08.457","description":"Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-20","CWE-74","CWE-94","CWE-116","CWE-913"],"vendors":[],"products":[],"references":[{"url":"https://kb.cert.org/vuls/id/212479","tags":[]},{"url":"https://www.kb.cert.org/vuls/id/212479","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"Sentry Seer is vulnerable to a multi-stage trust-boundary violation allowing unauthenticated attackers to execute arbitrary code through crafted telemetry events.","exploitability":"Exploitation requires an external attacker to submit fabricated events, but no specific access to the victim’s account or infrastructure is needed.","blast_radius":"If exploited, the vulnerability could lead to full control over the privileged automation environment, potentially leading to significant data loss or system compromise.","remediation":"Disable the affected feature or restrict access to the telemetry submission endpoint.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","telemetry","unauth","code-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T09:03:32.875Z"}}