What is CVE-2026-54364?
CentreStack versions before 17.4 contain a session variable injection vulnerability in the SelectProvider.aspx endpoint, allowing unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into the AccountName parameter. This can be exploited to manipulate session data. Upgrading to CentreStack version 17.4 or later is strongly recommended.
Azərbaycanca: CentreStack 17.4-dən əvvəlki versiyalarda SelectProvider.aspx endpoint-ə göndərilən AccountName parametrinə yeni sətir və tab simvolları daxil edilərək sessiya dəyişənlərinə injection həyata keçirilə bilər. Bu zəiflik autentifikasiya olunmamış hücumçulara ixtiyari sessiya dəyişənlərini manipulyasiya etməyə imkan verir. Dərhal CentreStack-i 17.4 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of CentreStack are affected by CVE-2026-54364?
Versions of CentreStack before 17.4 are affected.
Is authentication required to exploit CVE-2026-54364?
No, this vulnerability can be exploited by unauthenticated attackers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.