CVE-2026-54363: Use of Hard-coded Cryptographic Key in Gladinet CentreStack
CentreStack versions before 17.5 contain a critical vulnerability due to a hardcoded cryptographic key. This flaw allows unauthenticated attackers to forge encrypted tokens by exploiting a static entropy value used in encryption and decryption functions. Exploitation enables attackers to craft valid authentication headers and access privileged API endpoints, potentially obtaining domain administrator credentials and achieving unauthenticated remote code execution.
AI Analysis
Technical Summary
CVE-2026-54363 describes a vulnerability in Gladinet CentreStack prior to version 17.5 where a hardcoded cryptographic key is used as entropy in AccessTicket.Encrypt() and AccessTicket.Decrypt(). This static SysNumber value allows unauthenticated attackers to forge arbitrary encrypted tokens, including valid x-glad-auth headers. By exploiting this, attackers can call privileged API endpoints such as acquiretenantbackuptoken to obtain a domain administrator IdentityTicket, enabling a full unauthenticated remote code execution chain. The CVSS 4.0 base score is 9.3, indicating critical severity with network attack vector, no privileges or user interaction required, and high impact on confidentiality and integrity.
Potential Impact
The vulnerability allows unauthenticated remote attackers to forge encrypted tokens and gain privileged access to API endpoints. This can lead to obtaining domain administrator credentials and executing arbitrary code remotely without authentication, compromising the entire affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the affected versions are prior to 17.5, upgrading to version 17.5 or later is implied as a remediation step. Until an official fix or advisory is available, restrict access to CentreStack management interfaces and monitor for suspicious API calls.
CVE-2026-54363: Use of Hard-coded Cryptographic Key in Gladinet CentreStack
Description
CentreStack versions before 17.5 contain a critical vulnerability due to a hardcoded cryptographic key. This flaw allows unauthenticated attackers to forge encrypted tokens by exploiting a static entropy value used in encryption and decryption functions. Exploitation enables attackers to craft valid authentication headers and access privileged API endpoints, potentially obtaining domain administrator credentials and achieving unauthenticated remote code execution.
CVSS v4.0
Score 9.3critical
Affected software
pkg:github/gladinet/centrestackRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-54363 describes a vulnerability in Gladinet CentreStack prior to version 17.5 where a hardcoded cryptographic key is used as entropy in AccessTicket.Encrypt() and AccessTicket.Decrypt(). This static SysNumber value allows unauthenticated attackers to forge arbitrary encrypted tokens, including valid x-glad-auth headers. By exploiting this, attackers can call privileged API endpoints such as acquiretenantbackuptoken to obtain a domain administrator IdentityTicket, enabling a full unauthenticated remote code execution chain. The CVSS 4.0 base score is 9.3, indicating critical severity with network attack vector, no privileges or user interaction required, and high impact on confidentiality and integrity.
Potential Impact
The vulnerability allows unauthenticated remote attackers to forge encrypted tokens and gain privileged access to API endpoints. This can lead to obtaining domain administrator credentials and executing arbitrary code remotely without authentication, compromising the entire affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the affected versions are prior to 17.5, upgrading to version 17.5 or later is implied as a remediation step. Until an official fix or advisory is available, restrict access to CentreStack management interfaces and monitor for suspicious API calls.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-06-12T20:20:02.947Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6b49199c2644c7f816bfc6
Added to database: 07/30/2026, 12:52:41 UTC
Last enriched: 07/30/2026, 13:08:43 UTC
Last updated: 07/30/2026, 14:03:05 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.