CVE-2026-54367: 
Gladinet CentreStack vulnerability analysis and mitigation

Overview

CVE-2026-54367 is an authentication bypass vulnerability in Gladinet CentreStack that allows unauthenticated remote attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints lacking authorization checks. It affects all CentreStack versions before 17.2. The vulnerability was published on July 30, 2026, with a patch released in version 17.2. It carries a CVSS v3.1 base score of 8.6 (High) and a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, VulnCheck).

Technical details

The root cause is classified as CWE-306 (Missing Authentication for Critical Function): certain CentreStack API endpoints perform no authorization checks before processing requests. The vulnerability is further compounded by the use of a static, shared encryption key — attackers can use this hardcoded key to generate valid encrypted EntAcctId values that forge identifiers for any user GUID, including the system-wide cluster settings account. This allows an unauthenticated attacker to impersonate any user, including administrators, without any credentials. No special preconditions beyond network access to the CentreStack instance are required (GitHub Advisory, VulnCheck).

Impact

Successful exploitation allows unauthenticated network attackers to read, write, or delete account settings for any user account — including the system-wide cluster settings account — and enumerate hosted tenant domains and administrator identities. The integrity impact is high, as attackers can modify critical configuration data; confidentiality is partially compromised through exposure of tenant and administrator information; and availability is partially affected through potential deletion of account settings. The ability to target the cluster settings account and enumerate all tenant domains makes this particularly dangerous in multi-tenant CentreStack deployments (GitHub Advisory, VulnCheck).

Exploitability

As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (VulnCheck). The vulnerability is rated as automatable (NVD SSVC), meaning exploitation can be scripted without human interaction, lowering the barrier for mass scanning or opportunistic attacks. The EPSS score is approximately 0.188%, placing it in the 9th percentile for exploitation probability within 30 days. No threat actor attribution or CISA KEV catalog listing has been identified at this time (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing CentreStack instances running versions prior to 17.2 using tools such as Shodan or Censys, searching for CentreStack-specific HTTP response headers or login pages.
  2. Obtain static encryption key: Extract or identify the static shared encryption key used by CentreStack for EntAcctId generation — this key is hardcoded and shared across installations, making it obtainable through source analysis or prior research.
  3. Forge EntAcctId values: Using the static encryption key, generate valid encrypted EntAcctId values corresponding to target user GUIDs. To target the cluster settings account, use the known system-wide cluster settings GUID.
  4. Call unauthenticated API endpoints: Send HTTP requests to the exposed CentreStack API endpoints (lacking authorization checks), supplying the forged EntAcctId in the request to impersonate the target user without any credentials.
  5. Read, write, or delete account settings: Depending on the targeted endpoint, retrieve sensitive configuration data (tenant domains, administrator identities), modify account settings, or delete settings for any user including administrators (GitHub Advisory, VulnCheck).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to CentreStack API endpoints that normally require authentication; repeated requests with varying EntAcctId parameter values suggesting enumeration activity; unexpected API calls originating from unknown or external IP addresses.
  • Logs: CentreStack access logs showing API endpoint access without valid session tokens or authentication headers; high volume of requests to account settings endpoints from a single source IP; log entries reflecting read/write/delete operations on account settings without corresponding authenticated sessions.
  • Application: Unexpected modifications to tenant domain configurations or administrator account settings; newly enumerated or altered cluster-level settings with no corresponding change management record; evidence of administrator identity disclosure in application audit logs.

Mitigation and workarounds

Upgrade CentreStack to version 17.2 or later, which addresses this vulnerability by implementing proper authorization checks on the affected API endpoints (GitHub Advisory, VulnCheck). As an interim measure, implement network-level access controls (e.g., firewall rules, reverse proxy authentication) to restrict access to CentreStack API endpoints from untrusted networks. After patching, review account settings — particularly cluster-level and administrator settings — for any unauthorized modifications that may have occurred prior to remediation.

Community reactions

The vulnerability was reported by VulnCheck, which published a dedicated advisory (VulnCheck). The CISA vulnerability bulletin for the relevant week (SB26-215) referenced this CVE, indicating it was noted by government cybersecurity authorities. CTI aggregation platforms such as CTI Pilot highlighted the hardcoded key token forgery aspect of the vulnerability shortly after disclosure. No significant social media debate or major vendor statements beyond the VulnCheck advisory have been identified.

Additional resources


Source: This report was generated using AI

Related Gladinet CentreStack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54367HIGH8.8
  • Gladinet CentreStack logoGladinet CentreStack
  • cpe:2.3:a:gladinet:centrestack
NoYesJul 30, 2026
CVE-2026-54368HIGH8.7
  • Gladinet CentreStack logoGladinet CentreStack
  • cpe:2.3:a:gladinet:centrestack
NoYesJul 30, 2026
CVE-2026-54366HIGH8.7
  • Gladinet CentreStack logoGladinet CentreStack
  • cpe:2.3:a:gladinet:centrestack
NoYesJul 30, 2026
CVE-2026-54365HIGH8.7
  • Gladinet CentreStack logoGladinet CentreStack
  • cpe:2.3:a:gladinet:centrestack
NoYesJul 30, 2026
CVE-2026-54364MEDIUM6.9
  • Gladinet CentreStack logoGladinet CentreStack
  • cpe:2.3:a:gladinet:centrestack
NoYesJul 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management