Impact
N-central is affected by a pre‑authentication remote code execution flaw that allows an attacker to execute arbitrary code on the system before any authentication is performed. The vulnerability resides in the way N-central processes incoming requests, which can be exploited to run malicious code with the privileges of the application service. This can lead to full system compromise, data theft, and disruption of services.
Affected Systems
The flaw applies to all N‑able N‑central installations with versions prior to 2026.3.1.14. Users of the legacy N‑central product are at risk unless upgraded to the specified version or later.
Risk and Exploitability
The vulnerability carries a CVSS score of 10, denoting critical severity. The EPSS score is 13%, indicating a relatively low probability that an attacker will successfully exploit the flaw at this time. The flaw is listed in CISA’s KEV catalog, meaning that it has been actively exploited. While the description does not explicitly state the attack vector, it is inferred that the flaw can be exploited remotely and without authentication. The potential impact of an exploitation event is catastrophic, but current evidence points to a low likelihood of successful attacks unless the N‑central service is widely exposed.
OpenCVE Enrichment