Junglewise Threat Intelligence

CVE-2026-18556: N-able N-central authentication bypass via alternate path

CVE-2026-18556 · Severity: critical · CVSS 7.4 · Exploited in the wild · Published 2026-08-04

Executive brief

N-able N-central, a remote monitoring and management (RMM) platform used by IT service providers to manage client networks, contains a critical security flaw. This vulnerability allows an unauthorized person to bypass standard login procedures and gain access to the system. If exploited, an attacker could potentially take control of the management platform, leading to unauthorized access to sensitive client data and the ability to interfere with managed IT operations.

Technical details

An authentication bypass vulnerability (CWE-288) exists in N-able N-central through version 2026.1. The flaw involves the use of an alternate path or channel that allows an attacker to circumvent established authentication mechanisms. The attack vector is network-based and requires no prior privileges or user interaction, though it is rated with high attack complexity. Successful exploitation allows an attacker to bypass authentication entirely, potentially leading to full compromise of the N-central instance. N-able has released security updates to address this issue.

Affected products

  • N-able N-central through 2026.1

Timeline

  • 2026-08-01: disclosed: Initial N-able disclosure and NVD publication
  • 2026-08-02: patched: N-able security update blog post published
  • 2026-08-04: advisory: NVD assessment and CISA-ADP enrichment updated

Related threats