The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.
The vulnerability mechanism involves improper session handling in the login process via Entra SSO (Microsoft Entra ID). An attacker can perform so-called session rebinding — that is, bind an active, already authenticated session of another user to their own context. As a result, it is possible to take over the privileges of a logged-in user without knowing their login credentials. The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel).
A remote, unauthenticated attacker can gain unauthorized access to another user's account with full privileges, which may result in compromise of managed IT environments and unauthorized modification of configuration or data disclosure.
N-Able N-Central should be updated to version 2024.3 or later, according to the information contained in the manufacturer's official Release Notes and security advisory. If immediate update is not possible, consider temporarily disabling Entra SSO integration.
All N-Able N-Central deployments with Entra SSO support enabled in versions prior to 2024.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NN Able N Central
APPN-Able< 2024.3
Related vulnerabilities
Deserializacja niezaufanych danych w N-Able N-Central umożliwia RCE
OS Command Injection w N-able N-central (przed wersją 2025.3.1)
RCE przez deserialization w N-Able N-Central Software Probe
Authentication bypass via path traversal w N-Able N-Central
Authentication Bypass interfejsu użytkownika w N-Able N-Central