HIGH
CVE-2025-8876
CVSS
8.8
KEV
Description
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
Summary dbcve.org
N-able N-central contains an improper input validation vulnerability that allows authenticated attackers to inject and execute arbitrary OS commands. This occurs in versions prior to 2025.3.1 where user-supplied input is not properly sanitized before being passed to system shell operations.
Mitigation
Upgrade N-able N-central to version 2025.3.1 or later to remediate this vulnerability. If immediate patching is not possible, restrict administrative access to trusted personnel and implement network segmentation to limit exposure.
Weakness (CWE)
CWE-20
Improper Input Validation
CWE-78
OS Command Injection
EPSS Score
3.33%
Probability of exploitation in next 30 days
88.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.