Junglewise Threat Intelligence

CVE-2026-8364: Gladinet Triofox Server Agent missing authentication in Access Service

CVE-2026-8364 · Severity: critical · CVSS 9.8 · Published 2026-05-27

Technologies: Gladinet Triofox Server Agent. Vendors: Gladinet.

Executive brief

Gladinet Triofox Server Agent, a tool used to provide secure remote access to file servers, contains a vulnerability where its management service fails to require authentication. An attacker can remotely connect to the service to view, modify, or delete files on the server's mapped drives and change critical system settings. This could lead to the complete compromise of sensitive corporate data and the disruption of file-sharing operations.

Technical details

The Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages without requiring authentication (CWE-306). An unauthenticated remote attacker can interact with several endpoints, including /resources and /Settings, to perform file operations (list, view, add, change, delete) on the mapped Triofox Drive or manipulate the local SQLite configuration database (gsettings.db). Furthermore, attackers can exploit the /profile endpoint to perform administrative actions such as adding users. In some configurations, these requests can trigger authenticated communications with the Triofox web portal using the credentials of the currently logged-in management console user.

Affected products

  • Gladinet Triofox Server Agent 17.1.10488.57063

Timeline

  • 2026-05-27: advisory: Tenable Research Advisory TRA-2026-45 published
  • 2026-05-27: disclosed: CVE-2026-8364 published to NVD

References

Related threats