The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.
The vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and CWE-287 (Improper Authentication) consists of the ability to bypass authentication mechanisms of the N-Central server user interface. An unauthenticated remote attacker can exploit an alternative path or improperly implemented identity verification process to gain access to the interface without possessing valid credentials. The vulnerability was disclosed during an internal source code review of N-Central by the N-able team.
An attacker can gain unauthorized access to the N-Central management interface, which can consequently lead to takeover of managed devices, disclosure of sensitive data, or modification of IT environment configuration.
N-Central should be updated to version 2024.2 or newer, in accordance with information contained in the vendor's official Release Notes available at the address indicated in the references. It is also recommended to restrict network access to the N-Central management interface exclusively to trusted IP addresses.
All N-Able N-Central deployments in versions earlier than 2024.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NN Able N Central
APPN-Able< 2024.2
Related vulnerabilities
Deserializacja niezaufanych danych w N-Able N-Central umożliwia RCE
OS Command Injection w N-able N-central (przed wersją 2025.3.1)
RCE przez deserialization w N-Able N-Central Software Probe
Authentication bypass via path traversal w N-Able N-Central
Authentication Bypass w N-Able N-Central poprzez session rebinding (Entra SSO)