
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-54367 is an authentication bypass vulnerability in Gladinet CentreStack that allows unauthenticated remote attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints lacking authorization checks. It affects all CentreStack versions before 17.2. The vulnerability was published on July 30, 2026, with a patch released in version 17.2. It carries a CVSS v3.1 base score of 8.6 (High) and a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, VulnCheck).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function): certain CentreStack API endpoints perform no authorization checks before processing requests. The vulnerability is further compounded by the use of a static, shared encryption key — attackers can use this hardcoded key to generate valid encrypted EntAcctId values that forge identifiers for any user GUID, including the system-wide cluster settings account. This allows an unauthenticated attacker to impersonate any user, including administrators, without any credentials. No special preconditions beyond network access to the CentreStack instance are required (GitHub Advisory, VulnCheck).
Successful exploitation allows unauthenticated network attackers to read, write, or delete account settings for any user account — including the system-wide cluster settings account — and enumerate hosted tenant domains and administrator identities. The integrity impact is high, as attackers can modify critical configuration data; confidentiality is partially compromised through exposure of tenant and administrator information; and availability is partially affected through potential deletion of account settings. The ability to target the cluster settings account and enumerate all tenant domains makes this particularly dangerous in multi-tenant CentreStack deployments (GitHub Advisory, VulnCheck).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (VulnCheck). The vulnerability is rated as automatable (NVD SSVC), meaning exploitation can be scripted without human interaction, lowering the barrier for mass scanning or opportunistic attacks. The EPSS score is approximately 0.188%, placing it in the 9th percentile for exploitation probability within 30 days. No threat actor attribution or CISA KEV catalog listing has been identified at this time (GitHub Advisory).
EntAcctId generation — this key is hardcoded and shared across installations, making it obtainable through source analysis or prior research.EntAcctId values corresponding to target user GUIDs. To target the cluster settings account, use the known system-wide cluster settings GUID.EntAcctId in the request to impersonate the target user without any credentials.EntAcctId parameter values suggesting enumeration activity; unexpected API calls originating from unknown or external IP addresses.Upgrade CentreStack to version 17.2 or later, which addresses this vulnerability by implementing proper authorization checks on the affected API endpoints (GitHub Advisory, VulnCheck). As an interim measure, implement network-level access controls (e.g., firewall rules, reverse proxy authentication) to restrict access to CentreStack API endpoints from untrusted networks. After patching, review account settings — particularly cluster-level and administrator settings — for any unauthorized modifications that may have occurred prior to remediation.
The vulnerability was reported by VulnCheck, which published a dedicated advisory (VulnCheck). The CISA vulnerability bulletin for the relevant week (SB26-215) referenced this CVE, indicating it was noted by government cybersecurity authorities. CTI aggregation platforms such as CTI Pilot highlighted the hardcoded key token forgery aspect of the vulnerability shortly after disclosure. No significant social media debate or major vendor statements beyond the VulnCheck advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."