PatchSiren cyber security CVE debrief
CVE-2026-54365 Gladinet CVE debrief
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. The vulnerability has a CVSS score of 8.7 and a CVSS severity of HIGH. CentreStack users and administrators should review their deployments, assess potential exposure, and apply patches or updates to version 17.3 or later. They should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn. Additionally, they should verify their CentreStack versions and plan for updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions should be tracked, and remediated assets should be retested and closed only after evidence is documented. Asset inventory and vulnerability management processes should be updated to reflect this vulnerability. Rollback and change windows should be considered for updates. Source tracking and monitoring should be implemented to detect potential exploitation attempts.
- Vendor
- Gladinet
- Product
- CentreStack
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-30
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-30
- Advisory updated
- 2026-07-31
Who should care
CentreStack users and administrators, security teams monitoring for potential unauthenticated user creation attacks, and operators managing CentreStack deployments should be aware of this vulnerability. They should review their deployments, assess potential exposure, and apply patches or updates to version 17.3 or later. Security teams should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn. Additionally, they should verify their CentreStack versions and plan for updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions should be tracked, and remediated assets should be retested and closed only after evidence is documented. Asset inventory and vulnerability management processes should be updated to reflect this vulnerability. Rollback and change windows should be considered for updates. Source tracking and monitoring should be implemented to detect potential exploitation attempts. CentreStack users should also review the official CVE record and NVD details for further information on the vulnerability and its impact. They should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. The CVE record was published on 2026-07-30T13:16:51.503Z and has not been modified since then. The NVD detail provides additional information on the vulnerability and its severity. CentreStack users should prioritize patching to prevent potential unauthenticated user creation attacks. The vulnerability has a CVSS score of 8.7 and a CVSS severity of HIGH. The CVE record and NVD detail provide further information on the vulnerability and its impact. CentreStack users should review their deployments and apply patches or updates to version 17.3 or later. They should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API json, 7
Technical summary
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll. Attackers can exploit this by sending a malicious StorageConfigure parameter to specific API endpoints, triggering InternalImportAdUserByUPN() and creating arbitrary local OS user accounts. CentreStack users should prioritize patching to prevent potential unauthenticated user creation. The vulnerability allows for the creation of arbitrary directories on the server filesystem.
Defensive priority
CentreStack users should prioritize patching to prevent potential unauthenticated user creation.
Recommended defensive actions
- Apply patches or updates to CentreStack to version 17.3 or later
- Restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn
- Monitor for suspicious activity related to StorageConfigure parameter
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the official CVE record and NVD details for further information on the vulnerability and its impact
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE description indicates CentreStack before 17.3 has an unauthenticated deserialization vulnerability in GSNamespace.dll, allowing attackers to create arbitrary local OS user accounts. The vulnerability is triggered by supplying a crafted base64-encoded XML string to specific API endpoints. CentreStack users and administrators should verify their deployments, review official advisories, and apply patches or updates to version 17.3 or later. They should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T13:16:51.503Z and has not been modified since then.