Session Variable Injection Vulnerability in CentreStack by CentreStack
CVE-2026-54364

6.9MEDIUM

Key Information:

Vendor

Gladinet

Vendor
CVE Published:
30 July 2026

What is CVE-2026-54364?

CentreStack versions prior to 17.4 are subject to a session variable injection vulnerability. This weakness allows unauthenticated attackers to exploit the system by injecting arbitrary session variables through a crafted AccountName parameter in the SelectProvider.aspx endpoint. The vulnerability stems from insufficient input sanitization within the custom session serialization format, enabling attackers to bypass the IsValidRSession authentication mechanism and access restricted management pages.

Affected Version(s)

CentreStack 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PeterV @cfc security ltd
.