← Back to CVE List
Vulnerability Intelligence Report
CentreStack < 17.4 SQL Injection via x-glad-filter Header

CVE-2026-54368

CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers can exploit unsanitized interpolation of the Field parameter directly into SQL query strings to write arbitrary files to the server filesystem via PostgreSQL lo_from_bytea() and lo_export() functions, enabling remote code execution.

Injection No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.39%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-89 ↗Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Affected Products & Versions

Vendor Product Affected Versions
Gladinet CentreStack 0 < 17.4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.392%
Vulnerability Class
Injection

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-06-12T20:20:02
Published2026-07-30T12:26:49
Patch Date2026-07-28
Last Updated2026-08-14T16:50:22

LINK COPIED TO CLIPBOARD