Unauthenticated Deserialization Vulnerability in CentreStack
CVE-2026-54365

8.7HIGH

Key Information:

Vendor

Gladinet

Vendor
CVE Published:
30 July 2026

What is CVE-2026-54365?

CentreStack versions prior to 17.3 are affected by an unauthenticated deserialization vulnerability in the GSNamespace.dll file. This flaw enables attackers to exploit exposed API endpoints by injecting a malicious base64-encoded XML string. By manipulating the StorageConfigure parameter in specific endpoints like jsonimportuserbyupn and japiimportuserbyupn, an attacker can invoke the InternalImportAdUserByUPN() function, leading to the creation of arbitrary local OS user accounts. Further, this vulnerability allows for the potential execution of attacker-controlled commands, compromising the server's security integrity.

Affected Version(s)

CentreStack 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PeterV @cfc security ltd
.