Back

CRITICAL

N-central Authentication Bypass via Session Rebinding

Published Jul 1, 2024

Description

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass.

This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.

Affected products

Remediation

Vendor solution

Upgrade to N-central version 2024.3 or higher

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner N-able
Published Jul 1, 2024
Updated Aug 1, 2024
Reserved May 24, 2024
CISA Vulnrichment
Updated Jul 2, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a