Vulnerability Intelligence Report
CentreStack < 17.4 XXE via SharePoint Storage Configuration
CVE-2026-54366
CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the unauthenticated StorageConfig endpoint causing the server to fetch and parse attacker-controlled XML containing external DTD references, resulting in out-of-band file exfiltration of sensitive files such as Web.config, which may contain database credentials and cryptographic key material.
XML External Entity (XXE)
No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.29%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-611 ↗Improper Restriction of XML External Entity Reference
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Gladinet | CentreStack | 0 < 17.4 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2026-06-12T20:20:02 |
| Published | 2026-07-30T12:25:36 |
| Patch Date | 2026-07-28 |
| Last Updated | 2026-08-14T16:50:21 |
Community Chatter & Buzz