Junglewise Threat Intelligence

CVE-2026-54367: Gladinet CentreStack auth bypass in API endpoints

CVE-2026-54367 · Severity: high · CVSS 8.6 · Published 2026-07-30

Executive brief

CentreStack is a file-sharing and collaboration platform used by managed service providers to provide secure remote access to data. A security flaw allows unauthorized individuals to bypass login requirements and modify or delete critical account settings. This could lead to the exposure of administrator identities, the takeover of tenant accounts, or significant disruption to the file-sharing service.

Technical details

An authentication bypass vulnerability exists in CentreStack's API endpoints due to missing authorization checks (CWE-306). The flaw stems from the use of a static shared encryption key, which allows unauthenticated attackers to generate valid encrypted 'EntAcctId' values. By forging these identifiers for specific user GUIDs, including the system-wide cluster settings account, an attacker can enumerate hosted tenant domains and administrator identities. This enables the unauthorized modification or deletion of account configurations over the network without user interaction. The issue is addressed in version 17.2.

Affected products

  • Gladinet CentreStack before 17.2

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References

Related threats