{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/gladinet/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CentreStack (\u003c 17.3)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","deserialization","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["Gladinet"],"content_html":"\u003cp\u003eCentreStack versions prior to 17.3 contain a critical deserialization vulnerability residing in GSNamespace.dll. This vulnerability stems from improper handling of base64-encoded XML input provided to exposed web API endpoints. Unauthenticated remote attackers can leverage this flaw to trigger the InternalImportAdUserByUPN() method within the GladinetCloudMonitor.exe process. By supplying a malicious 'StorageConfigure' parameter, an attacker can coerce the application to invoke the Windows NetUserAdd API, resulting in the unauthorized creation of local OS user accounts. Furthermore, the attacker can influence filesystem operations, potentially leading to arbitrary directory creation on the host server. This vulnerability is significant as it provides a pathway for initial access, persistence, and privilege escalation on systems running CentreStack in a Windows environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies an internet-facing instance of CentreStack running version \u0026lt; 17.3.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious base64-encoded XML payload containing the 'StorageConfigure' parameter.\u003c/li\u003e\n\u003cli\u003eThe attacker submits the payload via an HTTP POST request to exposed API endpoints, specifically jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn.\u003c/li\u003e\n\u003cli\u003eThe GSNamespace.dll component deserializes the malicious XML input without proper validation.\u003c/li\u003e\n\u003cli\u003eThe application triggers the InternalImportAdUserByUPN() method, which is serviced by the GladinetCloudMonitor.exe process.\u003c/li\u003e\n\u003cli\u003eThe process invokes the native Windows NetUserAdd API using the parameters provided in the deserialized input.\u003c/li\u003e\n\u003cli\u003eA new, unauthorized local user account is created on the Windows host operating system.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves persistence or privilege escalation through the newly created account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain administrative-level control over the underlying Windows host by creating arbitrary local accounts. This bypasses authentication mechanisms, facilitating unauthorized access to the application and the host server. Given the nature of CentreStack as a file management and remote access solution, compromised instances could lead to full exfiltration of stored organizational data or provide a persistent foothold within the internal network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all CentreStack installations to version 17.3 or later immediately to patch CVE-2026-54365.\u003c/li\u003e\n\u003cli\u003eRestrict access to the CentreStack web interface and its associated API endpoints to authorized networks only using IP whitelisting at the network perimeter.\u003c/li\u003e\n\u003cli\u003eMonitor Windows security event logs (Event ID 4720) for the creation of new local user accounts, particularly those originating from the GladinetCloudMonitor.exe process or unexpected system accounts.\u003c/li\u003e\n\u003cli\u003eAudit filesystem activity for unusual directory creation in sensitive paths initiated by the Gladinet service user account.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T13:40:57Z","date_published":"2026-07-30T13:40:57Z","id":"https://feed.craftedsignal.io/briefs/2026-07-centrestack-deserialization/","summary":"An unauthenticated deserialization vulnerability in CentreStack allows remote attackers to create unauthorized local user accounts by sending crafted XML payloads to specific API endpoints.","title":"Unauthenticated Deserialization Vulnerability in CentreStack","url":"https://feed.craftedsignal.io/briefs/2026-07-centrestack-deserialization/"}],"language":"en","title":"CraftedSignal Threat Feed - Gladinet","version":"https://jsonfeed.org/version/1.1"}