← Vulnerability feed

Vulnerability record · CVE-2024-28200 · published 1 July 2024

CVE-2024-28200: N-able n-central authentication bypass via alternate path vulnerability

N Able · N Central

The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.

9.8 CVSS 3.1 Critical EPSS 1.9% · top 20.6% CWE-288 · Authentication bypass via alternate pathCWE-287 · Improper authentication
9.8CVSS 3.1 base score
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-28200 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-86218N-able N-central pre-auth remote code execution via static code injectionN-central contains a static code injection flaw (CWE-96) that allows remote code execution before authentication. The record states the issue affects…KEVEPSS 13%analysed9.4CVE-2025-8875N-able N-central deserialization of untrusted data allows code executionN-able N-central contains a deserialization of untrusted data flaw (CWE-502) that permits code execution. It affects N-central versions before 2025.3…KEVEPSS 1.9%analysed9.4CVE-2025-8876N-able N-central improper input validation leads to OS command injectionN-able N-central before 2025.3.1 fails to properly validate input, allowing OS command injection. Because N-central is a remote monitoring and manage…KEVEPSS 3.4%analysed8.2CVE-2026-18577N-able N-central incomplete patch enables auth bypass and account takeoverAn incomplete fix for CVE-2026-18556 leaves an alternate-path authentication bypass in N-able N-central through version 2026.3.1. Because the origina…KEVEPSS 15%analysed8.2CVE-2026-18556N-able N-central authentication bypass via alternate pathN-able N-central contains an authentication bypass (CWE-288) that lets an attacker reach protected functionality through an alternate path or channel…KEVEPSS 7.9%analysed10.0CVE-2025-11367N-able n-central deserialization of untrusted data vulnerabilityThe N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserializationEPSS 0.58%9.8CVE-2023-47132N-able n-central improper privilege management vulnerabilityAn issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.EPSS 0.55%9.4CVE-2025-11366N-able n-central path traversal vulnerabilityN-central < 2025.4 is vulnerable to authentication bypass via path traversalEPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2024-28200), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.