What is CVE-2026-54366?
CentreStack versions before 17.4 contain an unauthenticated XXE injection vulnerability. It allows remote attackers to exfiltrate arbitrary files by sending a malicious URL to the SharePoint storage configuration handler. Immediate upgrade to version 17.4 or later is required.
Azərbaycanca: CentreStack 17.4-dən əvvəlki versiyalarda autentifikasiya olunmamış XXE injection zəifliyi aşkar edilib. Bu, uzaqdan hücum edən şəxsə SharePoint storage konfiqurasiya idarəçisinə xüsusi URL göndərərək ixtiyari faylları oxumağa imkan verir. Dərhal 17.4 və ya daha yeni versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-611
FAQ2
Which versions of CentreStack are affected by CVE-2026-54366?
All CentreStack versions before 17.4 are affected.
What does this vulnerability allow a remote attacker to do?
An attacker can read arbitrary files by sending a malicious URL to the SharePoint storage configuration handler.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.