CVE-2026-54365: Gladinet CentreStack

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints to trigger InternalImportAdUserByUPN(), causing GladinetCloudMonitor.exe to invoke the NetUserAdd Windows API with attacker-controlled credentials and create arbitrary directories on the server filesystem.

Affected products

  • Gladinet CentreStack: before 17.3 (fixed in 17.3)

Published 2026-07-30. Last modified 2026-07-31.