SQL Injection Vulnerability in CentreStack by CentreStack
CVE-2026-54368
8.7HIGH
What is CVE-2026-54368?
CentreStack versions before 17.4 are susceptible to a SQL injection vulnerability within the GladDBFiles.SearchEx() and SearchExUnder() functions. This flaw allows authenticated attackers to manipulate SQL queries by sending a specially crafted x-glad-filter request header via the jsondir API endpoint. By exploiting this vulnerability, attackers can execute arbitrary SQL commands, which may lead to unauthorized file writing on the server's filesystem using PostgreSQL functions like lo_from_bytea() and lo_export(), potentially facilitating remote code execution.
Affected Version(s)
CentreStack 0
