N-central Hotfix 4 closes a distinct pre-authentication server-side code-execution path left after Hotfix 3.
The path is reachable by an unauthenticated network caller on an affected self-hosted server.
Affects
N-able N-central, a remote monitoring and management server used by MSPs and IT teams to administer fleets of endpoints.
What it enables
Unauthenticated remote code execution on an N-central management server
An unauthenticated network caller reaches the N-central server→↓Attacker-controlled input reaches a statically saved code path without proper directive neutralization→↓The server executes attacker-controlled code before authentication→↓The unauthenticated request path and attacker-controlled directive are not public.
Research leadDiff Hotfix 3 and Hotfix 4 to identify the newly corrected input path and determine what exposure or compromise evidence can be recovered from server logs.
Why this matters
A second pre-authentication execution path after the prior emergency hotfix makes Hotfix 4 an immediate corrective action rather than routine patch maintenance.
Detail and 1 source
Required access
Network reachability to a self-hosted N-central server, without credentials or user interaction
Affected versions
All versions before 2026.3.1.14
Attacker-controlled input reaches statically saved code without proper directive neutralization, producing server-side execution before authentication.
Hotfix 4, not Hotfix 3, is the fixed release identified by the vendor. The available material does not establish whether servers reject older installable images.
Evidence
The vendor CNA record establishes the pre-authentication RCE class, affected range, fixed version, and unauthenticated network vectorThe vendor advisory and Hotfix 4 release notes were directly retrievable
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.