Gladinet CentreStack was disclosed with multiple high-severity vulnerabilities affecting versions prior to 17.5, including an authentication bypass (CVE-2026-54367), a hardcoded-key token forgery issue (CVE-2026-54363), and a SQL injection flaw (CVE-2026-54368). The authentication bypass lets unauthenticated attackers forge encrypted EntAcctId values using a static shared key to read, modify, or delete arbitrary account settings, including cluster-wide configuration, while also enabling tenant-domain and administrator enumeration. The token forgery flaw stems from a static SysNumber value used in ticket encryption, allowing attackers to craft valid x-glad-auth headers and obtain privileged identity tokens from sensitive API endpoints.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
ThreatAft reported a four-CVE CentreStack vulnerability bundle comprising CVE-2026-54363, CVE-2026-54365, CVE-2026-54367, and CVE-2026-54368. The report said patched releases were available, recommended upgrading to CentreStack 17.5 or later, and noted no active exploitation had been confirmed at publication.
The Canadian Centre for Cyber Security published advisory AV26-765 stating that Gladinet CentreStack is affected by vulnerabilities. The notice urged users and administrators to review Gladinet's guidance and apply updates as they become available.
A SQL injection vulnerability affecting Gladinet CentreStack before version 17.4 was disclosed as CVE-2026-54368. Through a crafted x-glad-filter header to the jsondir API endpoint, an authenticated attacker can execute arbitrary SQL and potentially write files to the server, leading to remote code execution.
CVE-2026-54367 was disclosed as an unauthenticated authorization bypass in Gladinet CentreStack before version 17.2. The issue lets attackers forge EntAcctId values using a static shared key to read, write, or delete arbitrary account settings and enumerate tenants and administrators.
A hardcoded cryptographic key vulnerability in Gladinet CentreStack before version 17.5 was disclosed as CVE-2026-54363. The flaw allows unauthenticated token forgery via a static SysNumber value and can enable a remote code execution chain through privileged API access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.