CVE-2025-9316: N-central unauthenticated sessionID generation
Published Nov 12, 2025
·Updated
N-central < 2025.4 can generate sessionIDs for unauthenticated users
This issue affects N-central: before 2025.4.
Affected Software
1 affected component
N-able N-Central<2025.4
Event History
Nov 12, 2025
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Feb 28, 57989
Event
via FIRST·12:27 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9316?
CVE-2025-9316 has a medium severity rating due to its potential to compromise session management for unauthenticated users.
2
How do I fix CVE-2025-9316?
To fix CVE-2025-9316, upgrade your N-able N-central software to version 2025.4 or later.
3
What platforms are affected by CVE-2025-9316?
CVE-2025-9316 affects all versions of N-able N-central prior to version 2025.4.
4
What risks are associated with CVE-2025-9316?
The risks associated with CVE-2025-9316 include unauthorized access to sessions generated for unauthenticated users.
5
How can I verify if my N-central version is vulnerable to CVE-2025-9316?
You can verify your N-central version by checking the version number in your system's settings or dashboard.