Hardcoded Cryptographic Key Vulnerability in CentreStack by CentreStack
CVE-2026-54363

9.3CRITICAL

Key Information:

Vendor

Gladinet

Vendor
CVE Published:
30 July 2026

What is CVE-2026-54363?

CentreStack prior to version 17.5 is susceptible to a significant vulnerability involving a hardcoded cryptographic key. This flaw allows unauthenticated attackers to exploit a static SysNumber value, compromising the integrity of encrypted tokens utilized by the AccessTicket.Encrypt() and AccessTicket.Decrypt() methods. By leveraging this vulnerability, adversaries can create valid x-glad-auth headers and gain unauthorized access to sensitive API endpoints, such as acquiretenantbackuptoken. This results in the potential retrieval of a domain administrator IdentityTicket, paving the way for a complete and unauthenticated remote code execution exploit.

Affected Version(s)

CentreStack 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PeterV @cfc security ltd
.