{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/centrestack--17.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-54367"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CentreStack (\u003c 17.2)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cve-2026-54367","api-security"],"_cs_type":"advisory","_cs_vendors":["CentreStack"],"content_html":"\u003cp\u003eCentreStack versions prior to 17.2 contain a critical authentication bypass vulnerability (CVE-2026-54367) originating from exposed API endpoints that fail to enforce necessary authorization checks. By leveraging a static shared encryption key, an unauthenticated attacker can generate valid, encrypted EntAcctId values. These values allow the attacker to forge identifiers for any user GUID, including those associated with system-wide cluster settings. Successful exploitation permits an attacker to perform unauthorized read, write, and delete operations on arbitrary account settings, and provides the capability to enumerate hosted tenant domains and administrative identities. This flaw poses a significant risk to organizations relying on CentreStack for managed file services, as it enables deep unauthorized access to the platform configuration and user data structures.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to gain administrative-level visibility and control over the platform's account settings. This leads to the exposure of sensitive organizational tenant information, potential account takeover of administrative roles, and the ability to modify core system configurations. The compromise of tenant enumeration and administrative identity metadata significantly increases the risk of further targeted attacks against the organization's infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all CentreStack deployments to version 17.2 or later immediately to remediate CVE-2026-54367.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous, high-frequency POST or GET requests targeting API endpoints associated with user or cluster setting management.\u003c/li\u003e\n\u003cli\u003ePerform a security audit of current administrative accounts to ensure no unauthorized identities or modified settings were introduced while the system was unpatched.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T13:41:11Z","date_published":"2026-07-30T13:41:11Z","id":"https://feed.craftedsignal.io/briefs/2026-07-centrestack-auth-bypass/","summary":"CentreStack versions prior to 17.2 are vulnerable to an authentication bypass that allows unauthenticated attackers to manipulate account settings and enumerate system data via exposed API endpoints.","title":"Authentication Bypass Vulnerability in CentreStack","url":"https://feed.craftedsignal.io/briefs/2026-07-centrestack-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - CentreStack (\u003c 17.2)","version":"https://jsonfeed.org/version/1.1"}