N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

🚨SEVERITY: HIGH — CVSS 8.1Security Advisory

TL;DR 📌

  • N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
  • Highest CVSS: 8.1 (High).
  • Listed in CISA KEV (2026-08-03) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-18577.

What it is

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

For leadership 🧭

Executive summary. N-able’s N-central remote monitoring and management platform can be tricked into granting full administrator access without valid credentials, and this route is already being used against real deployments. Because N-central sits at the centre of managed service provider operations, this needs urgent attention rather than waiting for the next scheduled patch cycle.

Why it matters:

  • N-central is the console MSPs use to manage every client endpoint under contract, so an authentication bypass here potentially exposes every downstream customer network, not just the N-central server itself
  • The flaw sits in an alternate path or channel that survived an earlier attempted fix, meaning the previous remediation did not fully close off the login logic attackers are using
  • Confidentiality, integrity and availability are all rated high impact, consistent with full account takeover rather than partial information disclosure
  • Listed in CISA’s Known Exploited Vulnerabilities catalogue as of 3 August 2026, confirming this bypass is being used against N-central instances rather than remaining theoretical

Now / Next / Later:

  • Now: Check whether your N-central server is internet-facing, review recent administrator logins and session activity for anything unexplained, and confirm you are running a version later than the one that received the incomplete earlier fix.
  • Next: Apply the vendor’s corrected fixed release during your next available change window, then force a password and API key rotation for all N-central administrator and integration accounts.
  • Later: Restrict management access to N-central to a VPN or allowlisted IP range, and add monitoring for repeated authentication anomalies on the platform, since a prior patch attempt for this same login path was found to be incomplete.

Source