What is CVE-2026-54363?
CVE-2026-54363: CentreStack versions before 17.5 contain a hardcoded cryptographic key vulnerability. This allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all installations. Updating to version 17.5 or later is recommended.
Azərbaycanca: CVE-2026-54363: CentreStack-in 17.5-dən əvvəlki versiyalarında "hardcoded cryptographic key" zəifliyi mövcuddur ki, bu da autentifikasiya olunmamış hücumçulara statik SysNumber dəyərindən istifadə edərək ixtiyari şifrələnmiş tokenləri saxtalaşdırmağa imkan verir. Bu, bütün qurğularda AccessTicket.Encrypt() və AccessTicket.Decrypt() funksiyalarına təsir göstərir. CentreStack-i 17.5 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which versions of CentreStack are vulnerable to CVE-2026-54363?
All versions of CentreStack prior to 17.5 are vulnerable to this flaw.
How can attackers forge tokens in the CVE-2026-54363 vulnerability?
Attackers can forge arbitrary encrypted tokens without authentication by exploiting a static SysNumber value used across all installations in the AccessTicket.Encrypt() and AccessTicket.Decrypt() functions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.