CyberRota
← Ana sayfaya dön

CVE-2026-54366

HIGH · CVSS 7.5

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-30T13:16:51.640 · Çekilme zamanı: 2026-07-30T18:37:37.509151+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-54366
Severity
HIGH
CVSS
7.5
EPSS
Yok
SharePoint

Orijinal NVD Açıklaması

CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the unauthenticated StorageConfig endpoint causing the server to fetch and parse attacker-controlled XML containing external DTD references, resulting in out-of-band file exfiltration of sensitive files such as Web.config, which may contain database credentials and cryptographic key material.