User Impersonation Affecting sentry package, versions [21.12.0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-SENTRY-15325662
  • published22 Feb 2026
  • disclosed21 Feb 2026
  • creditMuhammad Qasim Munir

Introduced: 21 Feb 2026

CVE-2026-27197  (opens in a new tab)
CWE-290  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

Affected versions of this package are vulnerable to User Impersonation in the SAML SSO authentication process. An attacker can gain unauthorized access to user accounts by leveraging a malicious SAML Identity Provider and another organization configured on the same instance.

Notes:

  • This is only exploitable if more than one organization is configured, and requires the malicious user to have permissions to modify SSO settings for another organization in a multi-organization instance.
  • A fix was implemented in 26.2.1; however, Sentry has stopped publishing versions to PyPI (see https://github.com/getsentry/self-hosted/issues/1654)

Workaround

This vulnerability can be mitigated by implementing user account-based two-factor authentication, which prevents attackers from completing authentication with a victim's user account.

References

CVSS Base Scores

version 4.0
version 3.1