What is CVE-2026-54368?
A SQL injection vulnerability exists in CentreStack versions before 17.4, affecting the GladDBFiles.SearchEx() and SearchExUnder() functions via the jsondir API. Authenticated attackers can execute arbitrary SQL commands by sending a crafted 'x-glad-filter' request header, potentially compromising the database. Users should urgently upgrade to version 17.4 or later to resolve the issue.
Azərbaycanca: CentreStack-in 17.4-dən əvvəlki versiyalarında jsondir API-si vasitəsilə SQL injection zəifliyi aşkarlanıb. Bu, autentifikasiya olunmuş hücumçulara xüsusi hazırlanmış 'x-glad-filter' başlığı ilə verilənlər bazasında ixtiyari SQL əmrləri icra etməyə imkan verir. Dərhal CentreStack-i 17.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Does exploiting CVE-2026-54368 require the attacker to be authenticated?
Yes, this SQL injection vulnerability can be exploited by authenticated attackers.
What action is recommended to remediate this vulnerability?
Users should urgently upgrade to CentreStack version 17.4 or later to resolve the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.