关键信息 漏洞名称 Improper authentication on SAML SSO process allows user identity linking 严重性 Critical CVSS v3 base metrics - Attack vector: Network - Attack complexity: Low - Privileges required: None - User interaction: None - Scope: Unchanged - Confidentiality: High - Integrity: High - Availability: None Severity rating: 9.1 / 10 CVE ID: CVE-2026-27197 影响 Impact: A critical vulnerability was discovered in the SAML SSO implementation of Sentry. It allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. 受影响版本 Affected versions: >= 21.12.0, < 26.2.0 修复版本 Patched versions: 26.2.0 修复措施 Sentry SaaS: Fix deployed on February 18, 2026. Self-Hosted Sentry: Upgrade to version 26.2.0 or higher if multiple organizations are configured. 解决方案 Workaround: Enable two-factor authentication for user accounts to prevent exploitation. 参考 References: #108458