CVE-2026-54365 Details
Description
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints to trigger InternalImportAdUserByUPN(), causing GladinetCloudMonitor.exe to invoke the NetUserAdd Windows API with attacker-controlled credentials and create arbitrary directories on the server filesystem.
A deserialization vulnerability allowing unauthenticated attackers to create arbitrary local operating system user accounts has been identified in CentreStack versions prior to 17.3. This vulnerability resides in GSNamespace.dll and can be exploited by sending a crafted base64-encoded XML string to exposed API endpoints. Attackers can manipulate the StorageConfigure parameter and target the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints. This triggers the InternalImportAdUserByUPN() function, which causes GladinetCloudMonitor.exe to call the NetUserAdd Windows API with attacker-controlled credentials, resulting in the creation of unauthorized user accounts and arbitrary directories on the server filesystem.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 30, 2026CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CentreStack | < 17.3 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |
Volerion