Executive brief
CentreStack is a file-sharing and collaboration platform used by managed service providers to provide secure remote access to data. A security flaw allows unauthorized individuals to bypass login requirements and modify or delete critical account settings. This could lead to the exposure of administrator identities, the takeover of tenant accounts, or significant disruption to the file-sharing service.
Technical details
An authentication bypass vulnerability exists in CentreStack's API endpoints due to missing authorization checks (CWE-306). The flaw stems from the use of a static shared encryption key, which allows unauthenticated attackers to generate valid encrypted 'EntAcctId' values. By forging these identifiers for specific user GUIDs, including the system-wide cluster settings account, an attacker can enumerate hosted tenant domains and administrator identities. This enables the unauthorized modification or deletion of account configurations over the network without user interaction. The issue is addressed in version 17.2.
Affected products
- Gladinet CentreStack before 17.2
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory