Hardcoded Cryptographic Key Vulnerability in CentreStack by CentreStack
⚠️ CVE-Referenzen:
CVE-2026-54363
Gladinet - Centrestack - CRITICAL - CVE-2026-54363.
CentreStack prior to version 17.5 is susceptible to a significant vulnerability involving a hardcoded cryptographic key. This flaw allows unauthenticated attackers to exploit a static SysNumber value, compromising the integrity of encrypted tokens utilized by the AccessTicket.Encrypt() and AccessTicket.Decrypt() methods. By leveraging this vulnerability, adversaries can create valid x-glad-auth headers and gain unauthorized access to sensitive API endpoints, such as acquiretenantbackuptoken. This results in the potential retrieval of a domain administrator IdentityTicket, paving the way for a complete and unauthenticated remote code execution exploit.
Quelle: securityvulnerability.io