CVE-2024-8510: N-able N-central

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6.

Affected products

  • N-able N-central: before 2024.6 (fixed in 2024.6)

Published 2025-03-17. Last modified 2026-06-17.