SQL Injection Vulnerability in CentreStack by CentreStack
CVE-2026-54368

8.7HIGH

Key Information:

Vendor

Gladinet

Vendor
CVE Published:
30 July 2026

What is CVE-2026-54368?

CentreStack versions before 17.4 are susceptible to a SQL injection vulnerability within the GladDBFiles.SearchEx() and SearchExUnder() functions. This flaw allows authenticated attackers to manipulate SQL queries by sending a specially crafted x-glad-filter request header via the jsondir API endpoint. By exploiting this vulnerability, attackers can execute arbitrary SQL commands, which may lead to unauthorized file writing on the server's filesystem using PostgreSQL functions like lo_from_bytea() and lo_export(), potentially facilitating remote code execution.

Affected Version(s)

CentreStack 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PeterV @cfc security ltd
.