← Back

N Able

n-able

15 CVEs • 4 products

Products (4)

Click to collapse
Toggle
N Central
n-central
Take Control
take_control
Passportal
passportal

CVEs (15)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1N Able
1N Central
Jun 17, 2026
Nov 12, 2025
8.4 HIGH· v4
7.5 HIGH· v3
N/A· v2
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
1N Able
1N Central
Jun 17, 2026
Nov 12, 2025
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization
1N Able
1N Central
Jun 17, 2026
Nov 12, 2025
9.4 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
N-central < 2025.4 is vulnerable to authentication bypass via path traversal
1N Able
1N Central
Jun 17, 2026
Sep 10, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions.
1N Able
1N Central
Jun 17, 2026
Aug 21, 2025
N/A· v4
8.3 HIGH· v3
N/A· v2
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025....Show more
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.Show less
1N Able
1N Central
Jun 17, 2026
Aug 14, 2025
9.4 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
1N Able
1N Central
Jun 17, 2026
Aug 14, 2025
9.4 CRITICAL· v4
7.8 HIGH· v3
N/A· v2
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
1N Able
1N Central
Jun 17, 2026
Mar 17, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-c...Show more
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6.Show less
1N Able
1N Central
Jun 17, 2026
Jul 1, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of...Show more
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.Show less
1N Able
1N Central
Jun 17, 2026
Jul 1, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-c...Show more
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.Show less
1N Able
1Automation Manager
Jun 17, 2026
May 2, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Tem...Show more
The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an attacker to manipulate the process into performing arbitrary file deletions. We recommend upgrading to version 2.91.0.0Show less
1N Able
1N Central
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.
1N Able
1Passportal
Jun 17, 2026
Feb 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
1N Able
1Take Control
Jun 17, 2026
Sep 11, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file del...Show more
BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.Show less
1N Able
1N Central
Jun 17, 2026
Aug 4, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring function of the server.