Access control filter bypass allows unauthorised access to APIs
50Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 6.9epss 0.7%
from disclosure to weapon
Published on NVDSep 5
VulnCheck+5d
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
yesVulnCheck
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
N-able · N-central