vulns.co
/
GKData.io MCP

GitHub Security Lab · 1 min read

Sentry: resource ownership must match the authorized organization

CVE-2026-26004 concerned a missing organization constraint in event retrieval. A permission check on the active organization did not establish ownership of the requested object. GitHub Security Lab reports cross-organization event disclosure in tested Sentry 25.12.0.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Editorial lesson: carry tenant identity into resource resolution, rather than checking actor permissions and object lookup independently. The maintainer patch adds the organization constraint and regression coverage for cross-organization denial. Review equivalent response paths against the same invariant.

Before reading

  • Basic server-side authentication and authorization concepts

Context and limits

  • The reported case requires an authenticated user with event-read permission in their own organization. It establishes unauthorized reading, not modification or account takeover; no customer incident or measured data-loss total is supplied.
  • Research was reported December 23, 2025. Maintainer pull request 105601 was merged January 2, 2026. Reviewed sources do not establish a packaged fixed release or production rollout date; merge is not deployment.
  • The researcher says Sentry fixed the issue but declined to issue a CVE; GitHub assigned it February 10. Preserve this provenance rather than implying vendor-issued CVE publication.
  • Byline: Peter Stöckli. Discovery is credited to a GitHub Security Lab AI agent, reviewed by Peter Stöckli and Man Yue Mo. Learning prerequisites are editorial.

Sources and provenance

  1. GHSL-2025-130: Unauthorized access to event data across organizational boundaries in Sentry - CVE-2026-26004 GitHub Security Lab · reviewed 2026-10-03
  2. Add functional org filter to GroupEventJsonView (#105601) Sentry · reviewed 2026-10-03
  3. Add functional org filter to GroupEventJsonView Sentry · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software