PT-2026-66466 · Unknown · Centrestack
CVE-2026-54365
·
Published
2026-07-30
·
Updated
2026-07-31
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CentreStack versions prior to 17.3
Description
An unauthenticated deserialization issue exists in GSNamespace.dll. This allows remote attackers to create arbitrary local OS user accounts and create directories on the server filesystem by sending a crafted base64-encoded XML string. The attack is executed by providing a malicious
StorageConfigure parameter to the 'jsonimportuserbyupn', 'jsonimportuserbyupnex', or 'japiimportuserbyupn' API endpoints. This triggers the InternalImportAdUserByUPN() function, which leads GladinetCloudMonitor.exe to call the NetUserAdd Windows API using credentials controlled by the attacker.Recommendations
Update CentreStack to version 17.3 or later.
Restrict access to the 'jsonimportuserbyupn', 'jsonimportuserbyupnex', and 'japiimportuserbyupn' API endpoints to minimize the risk of exploitation.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centrestack