CVE-2024-28200: N-able N-central

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.

Affected products

  • N-able N-central: before 2024.2 (fixed in 2024.2)

Published 2024-07-01. Last modified 2026-06-17.