CVE-2026-54366 Details
Description
CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the unauthenticated StorageConfig endpoint causing the server to fetch and parse attacker-controlled XML containing external DTD references, resulting in out-of-band file exfiltration of sensitive files such as Web.config, which may contain database credentials and cryptographic key material.
A vulnerability allowing XML external entity (XXE) injection has been identified in CentreStack versions prior to 17.4. This vulnerability allows unauthenticated attackers to exfiltrate arbitrary files by sending a malicious URL to the SharePoint storage configuration handler. The crafted request is directed to the unauthenticated StorageConfig endpoint, prompting the server to fetch and parse attacker-controlled XML with external DTD references. This exploitation leads to out-of-band file exfiltration of sensitive files, such as Web.config, which may contain database credentials and cryptographic key material.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 30, 2026CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.centrestack.com/ | [email protected] | Vendor |
| https://www.vulncheck.com/advisories/centrestack-xxe-via-sharepoint-storage-configuration | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CentreStack | < 17.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |
Volerion