CVE-2025-8876: N-able N-Central Command Injection Vulnerability
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
Other sources
N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
N-able N-centralto a version that resolves this vulnerability.Fixed in 2025.3.1 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8876?
CVE-2025-8876 has been classified as a high severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2025-8876?
To mitigate CVE-2025-8876, update N-able N-central to version 2025.3.1 or later.
What is the impact of CVE-2025-8876?
CVE-2025-8876 can potentially allow an attacker to execute arbitrary commands on the operating system through improper input validation.
Which versions of N-able N-central are affected by CVE-2025-8876?
N-able N-central versions prior to 2025.3.1 are affected by CVE-2025-8876.
Is there a workaround for CVE-2025-8876?
Currently, the most effective resolution for CVE-2025-8876 is to upgrade to the patched version of N-able N-central.