CVE-2026-18556

9.5 CISA KEV

N-able · N-central

N-able N-central is affected by an authentication bypass vulnerability using an alternate path or channel, potentially allowing unauthorized access.

Executive summary

An authentication bypass vulnerability in N-able N-central exposes the platform to unauthorized access by remote, unauthenticated attackers.

Vulnerability

This vulnerability is classified as CWE-288, involving an authentication bypass via an alternate path or channel. The flaw allows an unauthenticated, remote attacker to gain access to the system without providing valid credentials.

Business impact

With a CVSS score of 8.2, this vulnerability poses a high risk to organizational security. Successful exploitation grants an attacker unauthorized access to the N-central platform, which is typically used for managing IT infrastructure, potentially leading to widespread compromise of managed endpoints and sensitive network data.

Remediation

Immediate Action: Apply the latest security updates provided by N-able immediately. If a patch is not yet available, consult the official N-able Uptime portal for specific guidance or temporary workarounds.

Proactive Monitoring: Monitor authentication logs for unusual login patterns, such as multiple failed attempts followed by a successful login from unrecognized IP addresses.

Compensating Controls: Place the N-central management interface behind a VPN or restrict access to specific, known IP addresses via firewall rules to limit exposure to the public internet.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this authentication bypass requires immediate attention from IT administrators. Organizations must verify their N-central versions and apply the vendor-supplied fix as soon as it is released to prevent potential unauthorized access and lateral movement within the network.

More N-able CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Added to CISA KEV confirmed active exploitation
  4. Published in the daily brief kev section, carried in 6 daily briefs, Aug 5 to Aug 10
  5. Deep Dive published
  6. Removed from the daily brief KEV coverage window elapsed