How to use this reference
Editorial lesson: carry tenant identity into resource resolution, rather than checking actor permissions and object lookup independently. The maintainer patch adds the organization constraint and regression coverage for cross-organization denial. Review equivalent response paths against the same invariant.
Before reading
- Basic server-side authentication and authorization concepts
Context and limits
- The reported case requires an authenticated user with event-read permission in their own organization. It establishes unauthorized reading, not modification or account takeover; no customer incident or measured data-loss total is supplied.
- Research was reported December 23, 2025. Maintainer pull request 105601 was merged January 2, 2026. Reviewed sources do not establish a packaged fixed release or production rollout date; merge is not deployment.
- The researcher says Sentry fixed the issue but declined to issue a CVE; GitHub assigned it February 10. Preserve this provenance rather than implying vendor-issued CVE publication.
- Byline: Peter Stöckli. Discovery is credited to a GitHub Security Lab AI agent, reviewed by Peter Stöckli and Man Yue Mo. Learning prerequisites are editorial.
Sources and provenance
- GHSL-2025-130: Unauthorized access to event data across organizational boundaries in Sentry - CVE-2026-26004 GitHub Security Lab · reviewed 2026-10-03
- Add functional org filter to GroupEventJsonView (#105601) Sentry · reviewed 2026-10-03
- Add functional org filter to GroupEventJsonView Sentry · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.