
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-54367 is an authentication bypass vulnerability in Gladinet CentreStack that allows unauthenticated remote attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints lacking authorization checks. All CentreStack versions prior to 17.2 are affected. The vulnerability was published on July 30, 2026, and assigned by VulnCheck. It carries a CVSS v3.1 base score of 8.6 (High) and a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function): certain CentreStack API endpoints perform no authorization checks before processing requests. The attack mechanism relies on the application's use of a static, shared encryption key — attackers can use this key to generate valid encrypted EntAcctId values that forge identifiers for any user GUID, including the system-wide cluster settings account. Because the key is static and shared, no prior authentication or account access is required, making the attack fully automatable over the network with low complexity. A secondary CWE-639 (Authorization Bypass Through User-Controlled Key) classification has also been estimated, reflecting the forged-identifier aspect of the exploit (GitHub Advisory, VulnCheck Advisory).
Successful exploitation allows unauthenticated network attackers to read, modify, or delete account settings for any user account — including the system-wide cluster settings account — without any credentials. This enables enumeration of hosted tenant domains and administrator identities, which can facilitate targeted follow-on attacks such as credential stuffing, phishing, or privilege escalation. The integrity impact is rated High, as attackers can alter critical configuration data; confidentiality and availability impacts are rated Low, reflecting the ability to read sensitive account metadata and potentially disrupt settings-dependent functionality (GitHub Advisory).
EntAcctId values corresponding to target user GUIDs, including the system-wide cluster settings account GUID.EntAcctId in the request to impersonate the target account without any authentication token or session.EntAcctId parameters); requests originating from unfamiliar or external IP addresses with no prior authenticated session.EntAcctId values suggesting enumeration activity.Gladinet has addressed this vulnerability in CentreStack version 17.2. Organizations should upgrade to version 17.2 or later as the primary remediation. As an interim measure, implement network-level access controls (e.g., firewall rules, reverse proxy authentication) to restrict exposure of CentreStack API endpoints to trusted networks only. After patching, administrators should review account settings and cluster configurations for any unauthorized modifications that may have occurred prior to the upgrade (GitHub Advisory, VulnCheck Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."