Impact
N-central is affected by a pre‑authentication remote code execution flaw that allows an attacker to execute arbitrary code on the system before any authentication is performed. The vulnerability resides in the way N-central processes incoming requests, which can be exploited to run malicious code with the privileges of the application service. This can lead to full system compromise, data theft, and disruption of services.
Affected Systems
The flaw applies to all N-able N-central installations with versions prior to 2026.3.1.14. Users of the legacy N-central product are at risk unless upgraded to the specified version or later.
Risk and Exploitability
The vulnerability is assigned a CVSS score of 10, indicating critical severity. The EPSS score is not publicly available, and the issue is not currently listed in CISA’s KEV catalog. The attack vector is inferred to be remote over the network, requiring no authentication to trigger the code execution. Given the high CVSS, the risk to affected systems is substantial and the likelihood of exploitation is high, especially if the N-central service is exposed to the internet or to untrusted networks.
OpenCVE Enrichment