CVE-2026-18577
N-able · N-central
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
Executive summary
An authentication bypass and account takeover vulnerability in N-able N-central could allow unauthenticated attackers to gain full administrative control over affected systems.
Vulnerability
This is an authentication bypass vulnerability (CWE-288) occurring when an alternate path or channel is used to interact with the system. It affects unauthenticated users, effectively nullifying intended access controls.
Business impact
The ability for an unauthenticated attacker to perform account takeover poses a critical risk to organizational infrastructure. With a CVSS score of 8.2, this vulnerability could lead to total system compromise, unauthorized data access, and the potential for lateral movement across the managed network.
Remediation
Immediate Action: Upgrade N-able N-central to version 2026.3.1.7 or apply the provided hotfix immediately as detailed in the vendor release notes.
Proactive Monitoring: Review administrative account activity and audit logs for suspicious logins or unauthorized changes to user permissions.
Compensating Controls: Restrict management interface access to trusted internal IP addresses and implement multi-factor authentication where possible, although bypasses may still pose a threat.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability is highly critical due to the potential for full account takeover. Administrators must treat this as a priority update and verify that the hotfix or upgrade is successfully applied across all N-central instances to prevent unauthorized system access.