CVE-2025-22146

Improper authentication on SAML SSO process allows user impersonation in sentry

Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. The Sentry SaaS fix was deployed on Jan 14, 2025. For self hosted users; if only a single organization is allowed `(SENTRY_SINGLE_ORGANIZATION = True)`, then no action is needed. Otherwise, users should upgrade to version 25.1.0 or higher. There are no known workarounds for this vulnerability.


We have discovered 42 live websites that are affected by CVE-2025-22146.

Run a Free Instant Scan




Affected Software

Product  Sentry Server
Category Error and Exception Monitoring
Vulnerable Domains42 live websites (76% of Sentry Server install base)
Vulnerable Versions
  • from 21.12 through 25.1
Vulnerable Versions Count8 versions ( 53% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Jan 15, 2025
  • Updated - Jan 15, 2025

Website Distribution by Country

Number of websites using CVE-2025-22146
United States14 websites



Germany9 websites
France4 websites
Russia3 websites
Switzerland2 websites
Hungary2 websites
Italy2 websites
Norway2 websites
Australia1 websites
China1 websites

Website Distribution by TLD

Number of websites using CVE-2025-22146
.com13 websites
.it5 websites
.de2 websites
.ch1 websites
.cn1 websites
.co1 websites
.com.au1 websites
.eu1 websites
.io1 websites
.ru1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-22146

Top websites that are affected by CVE-2025-22146. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.********.eu Switzerland***,***
***.***********.com United States***,***
********.com Germany*,***,***
******.******.com United States*,***,***
*****.com United States*,***,***
*******.****.ch Switzerland*,***,***
******.****.*.io GB*,***,***
******.****************.solutions United States*,***,***
******.****.biz Russia**,***,***
******.*******.com United States**,***,***
See full domain list

FAQ

CVE-2025-22146 is Improper Authentication in Sentry Server
A total of 42 websites have been identified as vulnerable to CVE-2025-22146, based on global website indexing conducted by WebTechSurvey.
The Sentry Server is affected by the CVE-2025-22146 vulnerability.
Sentry Server versions up to 25.1 are vulnerable to CVE-2025-22146.
CVE-2025-22146 is resolved in version 25.1 of Sentry Server.