


Perceptive Security
SOC/SIEM Consultancy

CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploi…
Published:
30 July 2026 at 00:00:00
Alert date:
30 July 2026 at 19:11:53
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities, Identity & Access
CentreStack versions before 17.5 contain a critical hardcoded cryptographic key vulnerability tracked as CVE-2026-54363. The flaw stems from a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() functions shared across all installations. Unauthenticated attackers can exploit this to forge arbitrary encrypted tokens and craft valid x-glad-auth headers. By leveraging these forged tokens, attackers can call privileged API endpoints such as acquiretenantbackuptoken to obtain a domain administrator IdentityTicket. This ultimately enables a complete unauthenticated remote code execution chain, making it a critical severity vulnerability. Organizations running CentreStack should upgrade to version 17.5 or later immediately.
Technical details
Mitigation steps:
Affected products:
CentreStack
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54363
https://www.centrestack.com/
https://www.vulncheck.com/advisories/centrestack-hardcoded-key-token-forgery-rce
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
