Junglewise Threat Intelligence

CVE-2026-54366: Gladinet CentreStack XXE in SharePoint storage configuration handler

CVE-2026-54366 · Severity: high · CVSS 7.5 · Published 2026-07-30

Executive brief

CentreStack, a file-sharing and remote access platform for managed service providers, contains a security flaw in its SharePoint storage configuration handler. An unauthenticated attacker can exploit this to remotely steal sensitive files from the server, such as configuration files containing database credentials or encryption keys. This could lead to a total compromise of the server and the data it manages for various clients.

Technical details

An XML External Entity (XXE) injection vulnerability exists in CentreStack versions prior to 17.4 within the SharePoint storage configuration handler. The vulnerability is located in the unauthenticated StorageConfig endpoint, which fails to properly restrict XML external entity references. An attacker can send a crafted request containing a malicious URL, forcing the server to fetch and parse attacker-controlled XML with external DTD references. This allows for out-of-band (OOB) exfiltration of sensitive local files, such as Web.config, which may contain database credentials and cryptographic keys. The issue is resolved in version 17.4.

Affected products

  • Gladinet CentreStack before 17.4

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References

Related threats