Skip to main content

Vendor/product archive

n-able / n-central CVEs

Beta · best-effort

14 CVEs tagged to n-able / n-central7 Critical, 6 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-18577

Published Aug 2, 2026

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CVSS 8.2 · High
evidence mentions
15
Buzz score
72.7
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-18556

Published Aug 1, 2026

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

CVSS 8.2 · High
evidence mentions
8
Buzz score
67.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-11700

Published Nov 12, 2025

N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure

CVSS 8.4 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-11367

Published Nov 12, 2025

The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-11366

Published Nov 12, 2025

N-central < 2025.4 is vulnerable to authentication bypass via path traversal

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10231

Published Sep 10, 2025

An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with e…

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-7051

Published Aug 21, 2025

On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in al…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-8876

Published Aug 14, 2025

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

CVSS 9.4 · Critical
evidence mentions
7
Buzz score
60.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-8875

Published Aug 14, 2025

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

CVSS 9.4 · Critical
evidence mentions
7
Buzz score
60.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-8510

Published Mar 17, 2025

N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5322

Published Jul 1, 2024

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is prese…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-28200

Published Jul 1, 2024

The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerab…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-47132

Published Feb 8, 2024

An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-30297

Published Aug 4, 2023

An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring function of the server.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1