CVE-2026-86218
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.41%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-96
- Published
- 2026-09-06
- Last modified
- 2026-09-09
Affected products
- N-able N-central
Weakness type
Related vulnerabilities
- CVE-2025-57707 — File Station 5
- CVE-2025-7825 — Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation
- CVE-2025-36595 — Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of...
- CVE-2015-2079 — Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution...
- CVE-2025-30091 — In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command....
- CVE-2024-13268 — Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032
- CVE-2024-13267 — Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031
- CVE-2024-13265 — Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029