← Vulnerability feed

Vulnerability record · CVE-2025-8876 · published 14 August 2025

CVE-2025-8876: N-able N-central improper input validation leads to OS command injection

N Able · N Central

N-able N-central before 2025.3.1 fails to properly validate input, allowing OS command injection. Because N-central is a remote monitoring and management platform, a compromise can expose managed endpoints and the administrative control plane. The flaw is rated critical (CVSS 4.0 score 9.4) and is listed in CISA KEV.

9.4 CVSS 4.0 Critical CISA KEV since 13 Aug 2025 EPSS 3.4% · top 11.4% CWE-20 · Improper input validationCWE-78 · OS command injection
9.4CVSS 4.0 base score
3.4%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 4.0 base score 9.4 with network reachability and CISA KEV listing indicating known exploitation.

What it is

N-able N-central before 2025.3.1 fails to properly validate input, allowing OS command injection. Because N-central is a remote monitoring and management platform, a compromise can expose managed endpoints and the administrative control plane. The flaw is rated critical (CVSS 4.0 score 9.4) and is listed in CISA KEV.

Impact

An authenticated attacker can execute arbitrary operating system commands on the N-central server, gaining high confidentiality, integrity and availability impact on the host and potentially on downstream managed systems.

Attack surface

Reachable over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), per the CVSS 4.0 vector. The description does not specify the exact endpoint or parameter, so the precise injection point is not documented in this record.

Exploitation

CVE-2025-8876 was added to CISA KEV on 2025-08-13 with a remediation due date of 2025-08-20, indicating known exploitation. EPSS 30-day probability is 0.0333 (87.996th percentile); no ransomware campaign use is documented.

What to do

  • Upgrade N-central to 2025.3.1 or later, per the vendor release notes.
  • If immediate patching is not possible, apply the mitigations in the vendor instructions referenced by CISA KEV or discontinue use of the product.
  • Restrict network access to the N-central administrative interface to trusted management networks.
  • Review and reduce accounts with access to the N-central server, and enforce least privilege.
  • Monitor for signs of compromise on the N-central host and any managed endpoints.

Detection

  • Hunt for unexpected child processes spawned by the N-central web/service processes on the server.
  • Review N-central and OS logs for command execution or shell activity around administrative requests.
  • Alert on unusual outbound connections from the N-central server to internal or external hosts.
  • Audit authentication and administrative activity for anomalous or new accounts on the N-central server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-8876 to the Known Exploited Vulnerabilities catalog on 13 August 2025 as "N-able N-Central Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 20 August 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-8876 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-86218N-able N-central pre-auth remote code execution via static code injectionN-central contains a static code injection flaw (CWE-96) that allows remote code execution before authentication. The record states the issue affects…KEVEPSS 13%analysed9.4CVE-2025-8875N-able N-central deserialization of untrusted data allows code executionN-able N-central contains a deserialization of untrusted data flaw (CWE-502) that permits code execution. It affects N-central versions before 2025.3…KEVEPSS 1.9%analysed8.2CVE-2026-18577N-able N-central incomplete patch enables auth bypass and account takeoverAn incomplete fix for CVE-2026-18556 leaves an alternate-path authentication bypass in N-able N-central through version 2026.3.1. Because the origina…KEVEPSS 15%analysed8.2CVE-2026-18556N-able N-central authentication bypass via alternate pathN-able N-central contains an authentication bypass (CWE-288) that lets an attacker reach protected functionality through an alternate path or channel…KEVEPSS 7.9%analysed10.0CVE-2025-11367N-able n-central deserialization of untrusted data vulnerabilityThe N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserializationEPSS 0.58%9.8CVE-2024-28200N-able n-central authentication bypass via alternate path vulnerabilityThe N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central p…EPSS 1.9%9.8CVE-2023-47132N-able n-central improper privilege management vulnerabilityAn issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.EPSS 0.55%9.4CVE-2025-11366N-able n-central path traversal vulnerabilityN-central < 2025.4 is vulnerable to authentication bypass via path traversalEPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2025-8876), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.