CVE-2026-18577

N-able · N-central

An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.

Executive summary

An authentication bypass and account takeover vulnerability in N-able N-central could allow unauthenticated attackers to gain full administrative control over affected systems.

Vulnerability

This is an authentication bypass vulnerability (CWE-288) occurring when an alternate path or channel is used to interact with the system. It affects unauthenticated users, effectively nullifying intended access controls.

Business impact

The ability for an unauthenticated attacker to perform account takeover poses a critical risk to organizational infrastructure. With a CVSS score of 8.2, this vulnerability could lead to total system compromise, unauthorized data access, and the potential for lateral movement across the managed network.

Remediation

Immediate Action: Upgrade N-able N-central to version 2026.3.1.7 or apply the provided hotfix immediately as detailed in the vendor release notes.

Proactive Monitoring: Review administrative account activity and audit logs for suspicious logins or unauthorized changes to user permissions.

Compensating Controls: Restrict management interface access to trusted internal IP addresses and implement multi-factor authentication where possible, although bypasses may still pose a threat.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability is highly critical due to the potential for full account takeover. Administrators must treat this as a priority update and verify that the hotfix or upgrade is successfully applied across all N-central instances to prevent unauthorized system access.