CVE-2026-54368
HIGHCentreStack < 17.4 SQL Injection via x-glad-filter Header
Title source: cnaDescription
CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers can exploit unsanitized interpolation of the Field parameter directly into SQL query strings to write arbitrary files to the server filesystem via PostgreSQL lo_from_bytea() and lo_export() functions, enabling remote code execution.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/centrestack-sql-injection-via-x-glad-filter-header
Scores
CVSS v3
8.8
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
Gladinet/CentreStack
< 17.4
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026