CVE-2025-11700
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:L
- EPSS probability
- 30.70%
- CWE
- CWE-611
- Published
- 2025-11-12
- Last modified
- 2026-03-12
Affected products
- N-able N-central
Weakness type
Related vulnerabilities
- CVE-2026-84941 — Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read
- CVE-2026-19596 — OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host
- CVE-2026-19614 — XML External Entity (XXE) Injection in CyberELF NanoXML
- CVE-2026-71375 — XXE Vulnerability in Cosminexus Component Container
- CVE-2026-76958 — XML External Entity (XXE) Vulnerability in SAP Integration Suite
- CVE-2026-17443 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-17444 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-81832 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs