CVE-2026-54367

HIGH

CentreStack < 17.2 Unauthenticated API Authorization Bypass

Title source: cna
STIX 2.1

Description

CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId values using the static shared encryption key to forge identifiers for any user GUID, including the system-wide cluster settings account, enabling enumeration of hosted tenant domains and administrator identities.

References (2)

Core 2
Core References
Product product
Product Homepage
https://www.centrestack.com/

Scores

CVSS v3 8.6
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
Gladinet/CentreStack < 17.2
Published Jul 30, 2026
Tracked Since Jul 30, 2026