PT-2026-66466 · Unknown · Centrestack

CVE-2026-54365

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions CentreStack versions prior to 17.3
Description An unauthenticated deserialization issue exists in GSNamespace.dll. This allows remote attackers to create arbitrary local OS user accounts and create directories on the server filesystem by sending a crafted base64-encoded XML string. The attack is executed by providing a malicious StorageConfigure parameter to the 'jsonimportuserbyupn', 'jsonimportuserbyupnex', or 'japiimportuserbyupn' API endpoints. This triggers the InternalImportAdUserByUPN() function, which leads GladinetCloudMonitor.exe to call the NetUserAdd Windows API using credentials controlled by the attacker.
Recommendations Update CentreStack to version 17.3 or later. Restrict access to the 'jsonimportuserbyupn', 'jsonimportuserbyupnex', and 'japiimportuserbyupn' API endpoints to minimize the risk of exploitation.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54365

Affected Products

Centrestack