{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/centrestack--17.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-54366"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CentreStack (\u003c 17.4)"],"_cs_severities":["high"],"_cs_tags":["xxe","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["CentreStack"],"content_html":"\u003cp\u003eCentreStack versions prior to 17.4 contain an XML external entity (XXE) injection vulnerability in the SharePoint storage configuration handler. This flaw allows an unauthenticated attacker to supply a malicious URL to the StorageConfig endpoint. The vulnerability exists because the application improperly processes user-supplied XML data without sufficient validation, permitting the inclusion of external DTD references. By sending a crafted request, an attacker can force the server to parse an external entity and exfiltrate the contents of local files out-of-band. This represents a significant risk, as the exfiltration of files such as Web.config can expose sensitive database credentials, configuration details, and cryptographic keys, leading to full system compromise or unauthorized access to backend storage.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies the target instance of CentreStack accessible via the internet.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an XML payload containing a malicious external DTD reference targeting a local file (e.g., Web.config).\u003c/li\u003e\n\u003cli\u003eAttacker sends an unauthenticated HTTP POST request to the /StorageConfig endpoint of the CentreStack application.\u003c/li\u003e\n\u003cli\u003eThe application processes the malicious XML payload within the SharePoint storage configuration handler.\u003c/li\u003e\n\u003cli\u003eThe server performs an out-of-band request to the attacker-controlled DTD server as instructed by the XXE payload.\u003c/li\u003e\n\u003cli\u003eThe server reads the target file content and includes it in the communication or triggers a side-channel exfiltration of the data.\u003c/li\u003e\n\u003cli\u003eThe attacker captures the exfiltrated sensitive data, such as database credentials or encryption keys, from their controlled server.\u003c/li\u003e\n\u003cli\u003eAttacker uses the stolen credentials to gain persistent or elevated access to the CentreStack backend and associated storage environments.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read arbitrary files from the filesystem of the hosting server. In typical enterprise deployments, this leads to the compromise of Web.config files, resulting in the theft of database connection strings, administrative credentials, and cryptographic keys. This impact compromises the confidentiality of all data managed by the CentreStack instance and enables further lateral movement into linked storage services like SharePoint.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of CentreStack to version 17.4 or later immediately to patch CVE-2026-54366.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to webserver access logs to detect potential XXE probe attempts targeting the StorageConfig endpoint.\u003c/li\u003e\n\u003cli\u003eReview web server logs for HTTP requests to the StorageConfig endpoint originating from unexpected or untrusted external IP addresses.\u003c/li\u003e\n\u003cli\u003eIf an instance was compromised, rotate all database credentials, API keys, and cryptographic secrets stored within Web.config and application settings.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T13:41:18Z","date_published":"2026-07-30T13:41:05Z","id":"https://feed.craftedsignal.io/briefs/2026-07-centrestack-xxe/","summary":"CentreStack versions prior to 17.4 are vulnerable to an unauthenticated XXE injection via the SharePoint storage configuration handler, allowing attackers to exfiltrate sensitive server-side files.","title":"CVE-2026-54366 CentreStack XXE Injection","url":"https://feed.craftedsignal.io/briefs/2026-07-centrestack-xxe/"}],"language":"en","title":"CraftedSignal Threat Feed - CentreStack (\u003c 17.4)","version":"https://jsonfeed.org/version/1.1"}