


Perceptive Security
SOC/SIEM Consultancy

CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploi…
Published:
30 July 2026 at 00:00:00
Alert date:
30 July 2026 at 16:01:29
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access, Zero-Day Vulnerabilities, Web Technologies
CentreStack versions before 17.5 contain a critical hardcoded cryptographic key vulnerability tracked as CVE-2026-54363. The flaw stems from a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() functions shared across all installations. Unauthenticated attackers can exploit this hardcoded key to forge arbitrary encrypted tokens and craft valid x-glad-auth headers. By calling privileged API endpoints such as acquiretenantbackuptoken, attackers can obtain a domain administrator IdentityTicket. This enables a complete unauthenticated remote code execution chain, representing a critical risk to all unpatched CentreStack deployments. The vulnerability affects all installations due to the shared static key, making it a systemic risk rather than an instance-specific one. Organizations running CentreStack should immediately upgrade to version 17.5 or later.
Technical details
Mitigation steps:
Affected products:
CentreStack
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54363
https://www.centrestack.com/
https://www.vulncheck.com/advisories/centrestack-hardcoded-key-token-forgery-rce
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
