CVE-2026-54366 HIGH

CVE-2026-54366: CentreStack < 17.4 XXE via SharePoint Storage Configuration

Vendor Gladinet
Product CentreStack
Weakness CWE-611 · XXE
Published July 30, 2026
Last update July 30, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the unauthenticated StorageConfig endpoint causing the server to fetch and parse attacker-controlled XML containing external DTD references, resulting in out-of-band file exfiltration of sensitive files such as Web.config, which may contain database credentials and cryptographic key material.

Key dates

02Disclosure timeline

July 30, 2026 CVE published
July 30, 2026 Record updated

Related vulnerabilities

04Related CVE