Back

HIGH

N-central Syslog Configuration Insecure Direct Object Reference

Published Aug 21, 2025

Description

On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.

Affected products

Remediation

Vendor solution

Upgrade to N-central version 2025.2 or higher.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner N-able
Published Aug 21, 2025
Updated Feb 26, 2026
Reserved Jul 3, 2025
CISA Vulnrichment
Updated Aug 22, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a