Authentication Bypass Vulnerability in N-central by N-able
CVE-2025-11366

9.4CRITICAL

Key Information:

Vendor

N-able

Status
Vendor
CVE Published:
12 November 2025

What is CVE-2025-11366?

N-central versions prior to 2025.4 are susceptible to an authentication bypass vulnerability due to a path traversal flaw. Attackers may exploit this weakness to gain unauthorized access to sensitive areas of the system without proper credentials, potentially leading to further exploitation. It is crucial for users to update to the latest version to mitigate this risk.

Affected Version(s)

N-central 0 < 2025.4

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11366 : Authentication Bypass Vulnerability in N-central by N-able