N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
🚨SEVERITY: HIGH — CVSS 8.1Security Advisory
TL;DR 📌
- N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
- Highest CVSS: 8.1 (High).
- Listed in CISA KEV (2026-08-03) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-18577.
What it is
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
For leadership 🧭
Executive summary. N-able’s N-central remote monitoring and management platform can be tricked into granting full administrator access without valid credentials, and this route is already being used against real deployments. Because N-central sits at the centre of managed service provider operations, this needs urgent attention rather than waiting for the next scheduled patch cycle.
Why it matters:
- N-central is the console MSPs use to manage every client endpoint under contract, so an authentication bypass here potentially exposes every downstream customer network, not just the N-central server itself
- The flaw sits in an alternate path or channel that survived an earlier attempted fix, meaning the previous remediation did not fully close off the login logic attackers are using
- Confidentiality, integrity and availability are all rated high impact, consistent with full account takeover rather than partial information disclosure
- Listed in CISA’s Known Exploited Vulnerabilities catalogue as of 3 August 2026, confirming this bypass is being used against N-central instances rather than remaining theoretical
Now / Next / Later:
- Now: Check whether your N-central server is internet-facing, review recent administrator logins and session activity for anything unexplained, and confirm you are running a version later than the one that received the incomplete earlier fix.
- Next: Apply the vendor’s corrected fixed release during your next available change window, then force a password and API key rotation for all N-central administrator and integration accounts.
- Later: Restrict management access to N-central to a VPN or allowlisted IP range, and add monitoring for repeated authentication anomalies on the platform, since a prior patch attempt for this same login path was found to be incomplete.