Database/Control plane, storage & DevOps

N-able N-central: Improper input validation
CVSS 8.8CVE-2025-8876Control plane, storage & DevOpsKnown exploitedcurated
Impact
Improper input validation -> OS command injection
Who can reach it
Network (remote)
What to do
Control-plane: patch to 2025.3.1+ immediately
References
Related entries
- N-able N-central: Incomplete patch for CVE-2026-18556CVE-2026-18577 · N-able N-centralHigh
- N-able N-central: Deserialization of untrusted data allowing local code execution on the RMM serverCVE-2025-8875 · N-able N-centralHigh
- N-able N-central: Authentication bypass using an alternate path or channel on the RMM serverCVE-2026-18556 · N-able N-centralHigh
- Grafana: symlink escape in plugin archive extraction gives remote code execution as the Grafana processCVE-2026-15815 · Grafana OSS / Enterprise (plugin archive extraction)High
- Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole): The RHOAI overlayCVE-2026-18951 · Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole)High
- NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID): An attacker who already has valid credentialsCVE-2026-22049 · NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.