What is CVE-2026-54365?
CVE-2026-54365 is an unauthenticated deserialization vulnerability in GSNamespace.dll in CentreStack versions prior to 17.3. It allows unauthenticated attackers to create arbitrary local OS user accounts by sending a crafted base64-encoded XML string to exposed API endpoints, necessitating immediate patching and API hardening.
Azərbaycanca: CVE-2026-54365: CentreStack-in 17.3-dən əvvəlki versiyalarında GSNamespace.dll faylında identifikasiyasız deserialization zəifliyi aşkarlanıb. Bu boşluq uzaqdan autentifikasiya olunmamış hücumçulara xüsusi hazırlanmış base64 kodlu XML vasitəsilə lokal OS istifadəçi hesabları yaratmağa imkan verir; təsirlənən sistemlərdə API endpoint-lərinin məhdudlaşdırılması və proqram təminatının yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which software is affected by CVE-2026-54365 and what can attackers achieve?
The vulnerability affects CentreStack versions prior to 17.3. By sending crafted base64-encoded XML to exposed API endpoints, unauthenticated attackers can create arbitrary local OS user accounts on affected systems.
What mitigations are recommended for CVE-2026-54365?
Immediate patching of the software and hardening of API endpoints are recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.