Session Variable Injection Vulnerability in CentreStack by CentreStack
CVE-2026-54364
6.9MEDIUM
What is CVE-2026-54364?
CentreStack versions prior to 17.4 are subject to a session variable injection vulnerability. This weakness allows unauthenticated attackers to exploit the system by injecting arbitrary session variables through a crafted AccountName parameter in the SelectProvider.aspx endpoint. The vulnerability stems from insufficient input sanitization within the custom session serialization format, enabling attackers to bypass the IsValidRSession authentication mechanism and access restricted management pages.
Affected Version(s)
CentreStack 0
