CVE-2026-54367

CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId values using the static shared encryption key to forge identifiers for any user GUID, including the system-wide cluster settings account, enabling enumeration of hosted tenant domains and administrator identities.
Configurations

No configuration.

History

30 Jul 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-30 13:16

Updated : 2026-07-30 16:45


NVD link : CVE-2026-54367

Mitre link : CVE-2026-54367

CVE.ORG link : CVE-2026-54367


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function