Security Advisory

CVE-2026-54365

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-30 12:25:05
Last updated 2026-07-31 22:51:40
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints to trigger InternalImportAdUserByUPN(), causing GladinetCloudMonitor.exe to invoke the NetUserAdd Windows API with attacker-controlled credentials and create arbitrary directories on the server filesystem.