CVE-2023-26829: Gladinet CentreStack

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new password for any valid user account, without needing the previous known password, resulting in a full authentication bypass.

Affected products

  • Gladinet CentreStack: before 13.5.9808 (fixed in 13.5.9808)

Published 2023-03-31. Last modified 2026-06-17.