CVE-2026-86218CWE-96
CVE-2026-86218
published September 6, 2026
What it is
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
The record
Technical detail
- CVSS
- 10.0 · NONE
- CVSS v4.0
- 10.0 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS
- 0.00411 · 34.3th percentile
- Weakness
- CWE-96 · Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
- Published
- 2026-09-06T07:17Z
References (1)
EPSS history
Timeline