CVE-2026-54368

CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers can exploit unsanitized interpolation of the Field parameter directly into SQL query strings to write arbitrary files to the server filesystem via PostgreSQL lo_from_bytea() and lo_export() functions, enabling remote code execution.
Configurations

No configuration.

History

30 Jul 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-30 13:16

Updated : 2026-07-30 16:45


NVD link : CVE-2026-54368

Mitre link : CVE-2026-54368

CVE.ORG link : CVE-2026-54368


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')