{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/centrestack--17.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-54363"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CentreStack (\u003c 17.5)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","remote-code-execution","hardcoded-key"],"_cs_type":"advisory","_cs_vendors":["CentreStack"],"content_html":"\u003cp\u003eCentreStack versions prior to 17.5 contain a critical cryptographic vulnerability where a hardcoded 'SysNumber' value is utilized as entropy for the AccessTicket.Encrypt() and AccessTicket.Decrypt() functions. Because this key is consistent across all installations, an unauthenticated attacker can effectively forge encrypted tokens. By crafting valid 'x-glad-auth' headers, an attacker can bypass authentication to access sensitive, privileged API endpoints. A primary objective identified for this exploit chain is the 'acquiretenantbackuptoken' endpoint, which facilitates the retrieval of a Domain Administrator IdentityTicket. Successful exploitation grants the attacker administrative control over the CentreStack instance, enabling remote code execution on the underlying server. This vulnerability represents a significant risk to organizations managing file server access and remote data synchronization via CentreStack, as it provides a direct path from unauthenticated network access to full system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies an internet-facing CentreStack instance.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the known hardcoded 'SysNumber' to replicate the encryption routine used for AccessTicket generation.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious 'x-glad-auth' HTTP header using the forged token.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted request to the 'acquiretenantbackuptoken' privileged API endpoint.\u003c/li\u003e\n\u003cli\u003eThe backend service validates the forged token as authentic due to the static entropy key.\u003c/li\u003e\n\u003cli\u003eThe server returns a high-privileged Domain Administrator IdentityTicket to the attacker.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the stolen IdentityTicket to authenticate to administrative API endpoints.\u003c/li\u003e\n\u003cli\u003eThe attacker interacts with file management or configuration APIs to execute arbitrary commands on the host server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to full unauthenticated remote code execution on the affected CentreStack server. This allows for complete data exfiltration, modification of system configurations, and lateral movement within the corporate network. Because this is a systemic vulnerability in the product's cryptographic implementation, all installations prior to version 17.5 are at risk of total compromise without requiring prior knowledge of legitimate user credentials.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade CentreStack instances to version 17.5 or later immediately as the primary remediation for CVE-2026-54363.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for anomalous 'POST' or 'GET' requests to the '/acquiretenantbackuptoken' API endpoint originating from non-authenticated or external IP addresses.\u003c/li\u003e\n\u003cli\u003eImplement strict network perimeter controls to restrict access to CentreStack management API endpoints to trusted internal IP ranges only.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules to inspect and filter suspicious 'x-glad-auth' headers that deviate from expected token formatting or originate from suspicious sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T13:40:33Z","date_published":"2026-07-30T13:40:33Z","id":"https://feed.craftedsignal.io/briefs/2026-07-centrestack-hardcoded-key/","summary":"CentreStack versions prior to 17.5 contain a hardcoded cryptographic key vulnerability, allowing unauthenticated attackers to forge authentication tokens and execute arbitrary code.","title":"Authentication Bypass and RCE in CentreStack via Hardcoded Cryptographic Key","url":"https://feed.craftedsignal.io/briefs/2026-07-centrestack-hardcoded-key/"}],"language":"en","title":"CraftedSignal Threat Feed - CentreStack (\u003c 17.5)","version":"https://jsonfeed.org/version/1.1"}