Description
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Published: 2026-09-06
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

N-central is affected by a pre‑authentication remote code execution flaw that allows an attacker to execute arbitrary code on the system before any authentication is performed. The vulnerability resides in the way N-central processes incoming requests, which can be exploited to run malicious code with the privileges of the application service. This can lead to full system compromise, data theft, and disruption of services.

Affected Systems

The flaw applies to all N-able N-central installations with versions prior to 2026.3.1.14. Users of the legacy N-central product are at risk unless upgraded to the specified version or later.

Risk and Exploitability

The vulnerability is assigned a CVSS score of 10, indicating critical severity. The EPSS score is not publicly available, and the issue is not currently listed in CISA’s KEV catalog. The attack vector is inferred to be remote over the network, requiring no authentication to trigger the code execution. Given the high CVSS, the risk to affected systems is substantial and the likelihood of exploitation is high, especially if the N-central service is exposed to the internet or to untrusted networks.

Generated by OpenCVE AI on September 6, 2026 at 03:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest N-central release (2026.3.1.14 or newer) to eliminate the vulnerability.
  • Restrict access to the N-central management interface using firewalls or network segmentation to limit exposure to trusted hosts.
  • Monitor authentication logs and monitor for suspicious HTTP requests that may indicate attempts to exploit the flaw.

Generated by OpenCVE AI on September 6, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 06 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Title pre-authentication remote code execution
Weaknesses CWE-96
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: N-able

Published:

Updated: 2026-09-06T02:15:28.824Z

Reserved: 2026-09-05T22:34:40.390Z

Link: CVE-2026-86218

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-06T03:17:17.373

Modified: 2026-09-06T03:17:17.373

Link: CVE-2026-86218

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T03:30:05Z

Weaknesses
  • CWE-96

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')