Impact
An authentication bypass exists in N-central software prior to version 2026.3 HF3, allowing attackers to gain access to internal APIs without valid credentials. This flaw can lead to unauthorized use of the system’s administrative functions, exposing sensitive configuration data and potentially enabling further compromise. The weakness is classified as improper authentication.
Affected Systems
The vulnerability affects N-able’s N-central product, all installations running a version older than 2026.3 HF3. No specific hardware or operating system constraints are noted; the issue resides entirely within the N-central application.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. Because the EPSS score is not available, the exploitation likelihood cannot be quantified, and the vulnerability is not yet listed in the CISA KEV catalog. However, given that the bypass targets internal APIs, an attacker would need network access to the N-central management network or a foothold within that network. The implied attack vector is likely network-based, possibly via a compromised or vulnerable client that can reach the internal endpoints. A successful exploitation grants attackers authentication-equivalent privileges to the system.
OpenCVE Enrichment