Vulnerability record · CVE-2025-8876 · published 14 August 2025
CVE-2025-8876: N-able N-central improper input validation leads to OS command injection
N Able · N Central
N-able N-central before 2025.3.1 fails to properly validate input, allowing OS command injection. Because N-central is a remote monitoring and management platform, a compromise can expose managed endpoints and the administrative control plane. The flaw is rated critical (CVSS 4.0 score 9.4) and is listed in CISA KEV.
Description
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 base score 9.4 with network reachability and CISA KEV listing indicating known exploitation.
What it is
N-able N-central before 2025.3.1 fails to properly validate input, allowing OS command injection. Because N-central is a remote monitoring and management platform, a compromise can expose managed endpoints and the administrative control plane. The flaw is rated critical (CVSS 4.0 score 9.4) and is listed in CISA KEV.
Impact
An authenticated attacker can execute arbitrary operating system commands on the N-central server, gaining high confidentiality, integrity and availability impact on the host and potentially on downstream managed systems.
Attack surface
Reachable over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), per the CVSS 4.0 vector. The description does not specify the exact endpoint or parameter, so the precise injection point is not documented in this record.
Exploitation
CVE-2025-8876 was added to CISA KEV on 2025-08-13 with a remediation due date of 2025-08-20, indicating known exploitation. EPSS 30-day probability is 0.0333 (87.996th percentile); no ransomware campaign use is documented.
What to do
- Upgrade N-central to 2025.3.1 or later, per the vendor release notes.
- If immediate patching is not possible, apply the mitigations in the vendor instructions referenced by CISA KEV or discontinue use of the product.
- Restrict network access to the N-central administrative interface to trusted management networks.
- Review and reduce accounts with access to the N-central server, and enforce least privilege.
- Monitor for signs of compromise on the N-central host and any managed endpoints.
Detection
- Hunt for unexpected child processes spawned by the N-central web/service processes on the server.
- Review N-central and OS logs for command execution or shell activity around administrative requests.
- Alert on unusual outbound connections from the N-central server to internal or external hosts.
- Audit authentication and administrative activity for anomalous or new accounts on the N-central server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-8876 to the Known Exploited Vulnerabilities catalog on 13 August 2025 as "N-able N-Central Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 20 August 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://status.n-able.com/2025/08/13/announcing-the-ga-of-n-central-2025-3-1/ | Release Notes |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8876 | US Government Resource |
Track CVE-2025-8876 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-8876), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.