CVE-2023-38035: Ivanti Sentry Authentication Bypass Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-08-22. EPSS: 100% chance of exploitation in the next 30 days.

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

Affected products

  • Ivanti MobileIron Sentry: up to and including 9.18.0

Published 2023-08-21. Last modified 2026-06-17.