CVE-2026-86218
10.0N-able · N-central
N-able N-central is vulnerable to a pre-authentication remote code execution flaw via static code injection, allowing unauthenticated attackers to execute arbitrary code on the target system.
Executive summary
A critical, unauthenticated remote code execution vulnerability in N-able N-central allows attackers to gain full system control without requiring prior access.
Vulnerability
This vulnerability, classified as CWE-96, involves improper neutralization of directives in statically saved code. It allows an unauthenticated attacker to inject and execute arbitrary code on the underlying server, compromising the integrity, availability, and confidentiality of the application.
Business impact
The CVSS score of 10.0 reflects the maximum possible risk, as the vulnerability is remotely exploitable without authentication or user interaction. Successful exploitation permits full system compromise, which could lead to significant data breaches, the deployment of ransomware, and total loss of control over managed network infrastructure.
Remediation
Immediate Action: Update N-able N-central to version 2026.3.1.14 or later immediately to apply the vendor-provided patch.
Proactive Monitoring: Review web server and system access logs for unusual request patterns, specifically looking for attempts to inject code or execute unauthorized scripts against the management interface.
Compensating Controls: Deploy or update rules on a Web Application Firewall (WAF) to block suspicious inbound traffic targeting the N-central management interface until the update is applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical severity and the nature of the N-able N-central platform as a central management tool, the risk to the organization is extreme. Administrators must prioritize the application of the 2026.3.1.14 patch across all instances immediately. Failure to address this vulnerability could result in total compromise of the managed environment.