{"id":"PYSEC-2026-1912","summary":"Privilege escalation via ApiTokensEndpoint","details":"### Impact\nAn attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with greater scopes, and use those tokens in other requests.\n\nThere is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via `https://your-self-hosted-sentry-installation/settings/account/api/auth-tokens/`.\n\n### Patches\nThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of [sentry](https://github.com/getsentry/sentry/releases/tag/23.7.2) and [self-hosted](https://github.com/getsentry/self-hosted/releases/tag/23.7.2).\n\n### Workarounds\nThere are no known workarounds.","aliases":["CVE-2023-39349","GHSA-9jcq-jf57-c62c"],"modified":"2026-07-07T17:47:52.918461748Z","published":"2026-07-07T11:45:21.756721Z","references":[{"type":"WEB","url":"https://github.com/getsentry/sentry/security/advisories/GHSA-9jcq-jf57-c62c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39349"},{"type":"WEB","url":"https://github.com/getsentry/sentry/pull/53850"},{"type":"WEB","url":"https://github.com/getsentry/sentry/commit/fad12c1150d1135edf9666ea72ca11bc110c1083"},{"type":"WEB","url":"https://github.com/getsentry/self-hosted/releases/tag/23.7.2"},{"type":"PACKAGE","url":"https://github.com/getsentry/sentry"},{"type":"WEB","url":"https://github.com/getsentry/sentry/releases/tag/23.7.2"},{"type":"PACKAGE","url":"https://pypi.org/project/sentry"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9jcq-jf57-c62c"}],"affected":[{"package":{"name":"sentry","ecosystem":"PyPI","purl":"pkg:pypi/sentry"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"22.1.0"},{"fixed":"23.7.2"}]}],"versions":["22.1.0","22.10.0","22.11.0","22.12.0","22.2.0","22.3.0","22.4.0","22.5.0","22.6.0","22.7.0","22.8.0","22.9.0","23.1.0","23.1.1","23.2.0","23.3.0","23.3.1","23.4.0","23.5.0","23.5.1","23.5.2","23.6.0","23.6.1","23.6.2","23.7.0","23.7.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/sentry/PYSEC-2026-1912.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}