Impact
A vulnerability in the N‑central internal API access control filter permits an unauthorised party to invoke internal APIs that are otherwise protected. The flaw effectively bypasses the intended authorization checks, allowing leakage or manipulation of data exposed by those APIs. This weakness corresponds to CWE‑791 and provides a path for non‑privileged users to access sensitive system functions.
Affected Systems
Systems affected are those running N‑central by N‑Able. The issue exists in versions released before the 2026.3 HF3 update and before the 2026.4 release, for which the fix applies. Administrators should verify the installed version and ensure it is at least 2026.3 HF3 or 2026.4 to remove the vulnerability.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, and the EPSS score is not available, so the precise likelihood of exploitation is unknown. The vulnerability is not included in CISA’s KEV catalog. Attackers can potentially exploit the bypass through internal network traffic or by sending crafted requests to the API endpoints; the exact attack vector is inferred from the description, as it is an internal API filter bypass.
OpenCVE Enrichment