Vendor
high
advisory
Authentication Bypass Vulnerability in CentreStack
1 TTP 1 CVECentreStack versions prior to 17.2 are vulnerable to an authentication bypass that allows unauthenticated attackers to manipulate account settings and enumerate system data via exposed API endpoints.
CentreStack
authentication-bypass
cve-2026-54367
api-security
1t
1c
high
advisory
CVE-2026-54366 CentreStack XXE Injection
1 rule 2 TTPs 1 CVECentreStack versions prior to 17.4 are vulnerable to an unauthenticated XXE injection via the SharePoint storage configuration handler, allowing attackers to exfiltrate sensitive server-side files.
CentreStack
xxe
vulnerability
web-application
1r
2t
1c
critical
advisory
Authentication Bypass and RCE in CentreStack via Hardcoded Cryptographic Key
1 TTP 1 CVECentreStack versions prior to 17.5 contain a hardcoded cryptographic key vulnerability, allowing unauthenticated attackers to forge authentication tokens and execute arbitrary code.
CentreStack
authentication-bypass
remote-code-execution
hardcoded-key
1t
1c