CyberRota
← Ana sayfaya dön

CVE-2026-54365

HIGH · CVSS 7.5

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-30T13:16:51.503 · Çekilme zamanı: 2026-07-30T18:37:37.465695+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-54365
Severity
HIGH
CVSS
7.5
EPSS
Yok
Windows

Orijinal NVD Açıklaması

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints to trigger InternalImportAdUserByUPN(), causing GladinetCloudMonitor.exe to invoke the NetUserAdd Windows API with attacker-controlled credentials and create arbitrary directories on the server filesystem.