CVE-2026-54368

HIGH

CentreStack < 17.4 SQL Injection via x-glad-filter Header

Title source: cna
STIX 2.1

Description

CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers can exploit unsanitized interpolation of the Field parameter directly into SQL query strings to write arbitrary files to the server filesystem via PostgreSQL lo_from_bytea() and lo_export() functions, enabling remote code execution.

References (2)

Core 2
Core References
Product product
Product Homepage
https://www.centrestack.com/

Scores

CVSS v3 8.8
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
Gladinet/CentreStack < 17.4
Published Jul 30, 2026
Tracked Since Jul 30, 2026