N-central < 2025.4 is vulnerable to authentication bypass via path traversal
The vulnerability classified as CWE-22 (path traversal) allows an attacker to manipulate network request paths in such a way as to bypass the application's authentication mechanisms. An attacker with only a low-privilege account (PR:L) can send a specially crafted HTTP request containing path traversal sequences that result in access to protected resources without the required authorization. The attack vector is network-based, without the need for physical access or user interaction on the victim's side.
Successful exploitation of this vulnerability allows an attacker to bypass authentication mechanisms and gain unauthorized access to the N-Central system, which according to the CVSS vector involves a high impact on the confidentiality, integrity, and availability of both the system itself and related systems.
N-Able N-Central must be immediately updated to version 2025.4 or later. Detailed information is available in the official security bulletin from the vendor at the address indicated in the references.
N-Able N-Central in versions prior to 2025.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XN Able N Central
APPN-Able< 2025.4
Related vulnerabilities
Deserializacja niezaufanych danych w N-Able N-Central umożliwia RCE
OS Command Injection w N-able N-central (przed wersją 2025.3.1)
RCE przez deserialization w N-Able N-Central Software Probe
Authentication Bypass interfejsu użytkownika w N-Able N-Central
Authentication Bypass w N-Able N-Central poprzez session rebinding (Entra SSO)