CVE-2026-54367
Deferred Deferred - Pending Action

Authentication Bypass in CentreStack via Forged EntAcctId

Vulnerability report for CVE-2026-54367, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: VulnCheck

Description

CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId values using the static shared encryption key to forge identifiers for any user GUID, including the system-wide cluster settings account, enabling enumeration of hosted tenant domains and administrator identities.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
centrestack centrestack to 17.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CentreStack before version 17.2 has an authentication bypass flaw in its API endpoints. Attackers can exploit this to read, write, or delete account settings without authentication. They forge encrypted identifiers using a static shared key to impersonate any user, including system accounts, enabling unauthorized access and configuration changes.

Detection Guidance

To detect this vulnerability, check if CentreStack versions prior to 17.2 are running on your system. Inspect network traffic for unauthenticated API requests to exposed endpoints that manipulate account settings. Look for unusual encrypted EntAcctId values in API responses or requests.

Impact Analysis

This vulnerability allows attackers to gain unauthorized access to your CentreStack account, modify or delete settings, and potentially access sensitive data. If you use CentreStack for file storage or collaboration, attackers could tamper with files, steal information, or disrupt services.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties, fines, or reputational damage due to exposed sensitive data.

Mitigation Strategies

Immediately upgrade CentreStack to version 17.2 or later to patch the vulnerability. Disable or restrict access to exposed API endpoints until the update is applied. Review and audit account settings for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54367. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart