PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54365 Gladinet CVE debrief

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. The vulnerability has a CVSS score of 8.7 and a CVSS severity of HIGH. CentreStack users and administrators should review their deployments, assess potential exposure, and apply patches or updates to version 17.3 or later. They should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn. Additionally, they should verify their CentreStack versions and plan for updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions should be tracked, and remediated assets should be retested and closed only after evidence is documented. Asset inventory and vulnerability management processes should be updated to reflect this vulnerability. Rollback and change windows should be considered for updates. Source tracking and monitoring should be implemented to detect potential exploitation attempts.

Vendor
Gladinet
Product
CentreStack
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-07-31
Advisory published
2026-07-30
Advisory updated
2026-07-31

Who should care

CentreStack users and administrators, security teams monitoring for potential unauthenticated user creation attacks, and operators managing CentreStack deployments should be aware of this vulnerability. They should review their deployments, assess potential exposure, and apply patches or updates to version 17.3 or later. Security teams should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn. Additionally, they should verify their CentreStack versions and plan for updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions should be tracked, and remediated assets should be retested and closed only after evidence is documented. Asset inventory and vulnerability management processes should be updated to reflect this vulnerability. Rollback and change windows should be considered for updates. Source tracking and monitoring should be implemented to detect potential exploitation attempts. CentreStack users should also review the official CVE record and NVD details for further information on the vulnerability and its impact. They should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. The CVE record was published on 2026-07-30T13:16:51.503Z and has not been modified since then. The NVD detail provides additional information on the vulnerability and its severity. CentreStack users should prioritize patching to prevent potential unauthenticated user creation attacks. The vulnerability has a CVSS score of 8.7 and a CVSS severity of HIGH. The CVE record and NVD detail provide further information on the vulnerability and its impact. CentreStack users should review their deployments and apply patches or updates to version 17.3 or later. They should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API json, 7

Technical summary

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll. Attackers can exploit this by sending a malicious StorageConfigure parameter to specific API endpoints, triggering InternalImportAdUserByUPN() and creating arbitrary local OS user accounts. CentreStack users should prioritize patching to prevent potential unauthenticated user creation. The vulnerability allows for the creation of arbitrary directories on the server filesystem.

Defensive priority

CentreStack users should prioritize patching to prevent potential unauthenticated user creation.

Recommended defensive actions

  • Apply patches or updates to CentreStack to version 17.3 or later
  • Restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn
  • Monitor for suspicious activity related to StorageConfigure parameter
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the official CVE record and NVD details for further information on the vulnerability and its impact
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE description indicates CentreStack before 17.3 has an unauthenticated deserialization vulnerability in GSNamespace.dll, allowing attackers to create arbitrary local OS user accounts. The vulnerability is triggered by supplying a crafted base64-encoded XML string to specific API endpoints. CentreStack users and administrators should verify their deployments, review official advisories, and apply patches or updates to version 17.3 or later. They should also monitor for suspicious activity related to StorageConfigure parameter and restrict access to API endpoints jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-54365 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-54365

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-54365 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54365

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.