PatchSiren cyber security CVE debrief
CVE-2026-54365 Gladinet CVE debrief
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. The vulnerability has a CVSS score of 8.7 and a CVSS severity of HIGH. CentreStack users and administrators should review their deployments, assess potential exposure, and apply patches or updates to version 17.3 or later. They should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn. Additionally, they should verify their CentreStack versions and plan for updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions should be tracked, and remediated assets should be retested and closed only after evidence is documented. Asset inventory and vulnerability management processes should be updated to reflect this vulnerability. Rollback and change windows should be considered for updates. Source tracking and monitoring should be implemented to detect potential exploitation attempts.
- Vendor
- Gladinet
- Product
- CentreStack
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-30
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-30
- Advisory updated
- 2026-07-31
Who should care
CentreStack users and administrators, security teams monitoring for potential unauthenticated user creation attacks, and operators managing CentreStack deployments should be aware of this vulnerability. They should review their deployments, assess potential exposure, and apply patches or updates to version 17.3 or later. Security teams should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn. Additionally, they should verify their CentreStack versions and plan for updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions should be tracked, and remediated assets should be retested and closed only after evidence is documented. Asset inventory and vulnerability management processes should be updated to reflect this vulnerability. Rollback and change windows should be considered for updates. Source tracking and monitoring should be implemented to detect potential exploitation attempts. CentreStack users should also review the official CVE record and NVD details for further information on the vulnerability and its impact. They should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. The CVE record was published on 2026-07-30T13:16:51.503Z and has not been modified since then. The NVD detail provides additional information on the vulnerability and its severity. CentreStack users should prioritize patching to prevent potential unauthenticated user creation attacks. The vulnerability has a CVSS score of 8.7 and a CVSS severity of HIGH. The CVE record and NVD detail provide further information on the vulnerability and its impact. CentreStack users should review their deployments and apply patches or updates to version 17.3 or later. They should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API json, 7
Technical summary
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll. Attackers can exploit this by sending a malicious StorageConfigure parameter to specific API endpoints, triggering InternalImportAdUserByUPN() and creating arbitrary local OS user accounts. CentreStack users should prioritize patching to prevent potential unauthenticated user creation. The vulnerability allows for the creation of arbitrary directories on the server filesystem.
Defensive priority
CentreStack users should prioritize patching to prevent potential unauthenticated user creation.
Recommended defensive actions
- Apply patches or updates to CentreStack to version 17.3 or later
- Restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn
- Monitor for suspicious activity related to StorageConfigure parameter
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the official CVE record and NVD details for further information on the vulnerability and its impact
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE description indicates CentreStack before 17.3 has an unauthenticated deserialization vulnerability in GSNamespace.dll, allowing attackers to create arbitrary local OS user accounts. The vulnerability is triggered by supplying a crafted base64-encoded XML string to specific API endpoints. CentreStack users and administrators should verify their deployments, review official advisories, and apply patches or updates to version 17.3 or later. They should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54365 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54365
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54365 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54365
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.centrestack.com/
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/centrestack-unauthenticated-user-creation-via-deserialization-in-gsnamespace-dll
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.