N-central Pre-Authentication Remote Code Execution
Pre-authentication remote code execution in N-able N-central via static code injection. Network-accessible, no credentials required. Fixed in 2026.3.1.14.
- Vendor
- N-able
- Product
- N-central
- CVSS
- 10.0
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
N-able’s N-central remote monitoring and management platform contains a pre-authentication remote code execution vulnerability in all versions before 2026.3.1.14. Classified as CWE-96 (static code injection), the flaw allows an unauthenticated attacker with network access to the server to execute arbitrary code on the host. No credentials and no user interaction are required.
The vulnerability is scored at CVSS 4.0: 10.0, the maximum, with a fully network-accessible attack vector (AV:N), low attack complexity (AC:L), no privileges required (PR:N), and no user interaction (UI:N). All confidentiality, integrity, and availability impact dimensions are rated high for both the vulnerable system and downstream scope.
N-able released version 2026.3.1.14 to address the flaw. No workarounds are documented in the advisory. Instances that cannot immediately receive the update should be isolated from external network access.
See the full coverage article for context on the exploitation risk in MSP environments.
