Executive brief
N-able N-central, a remote monitoring and management platform used by IT service providers to manage client networks, contains a critical security flaw. This vulnerability allows an unauthorized attacker to bypass security checks and take over user accounts. If exploited, an attacker could gain full control over the management console, potentially impacting all client systems managed through the platform.
Technical details
N-able N-central is vulnerable to an authentication bypass using an alternate path or channel (CWE-288). This issue stems from an incomplete patch for CVE-2026-18556. A remote, unauthenticated attacker can exploit this flaw to bypass authentication mechanisms and achieve full account takeover. The vulnerability affects N-central versions through 2026.3.1. N-able has released N-central 2026.3 Hotfix 1 (version 2026.3.1.7) to address this issue. The vulnerability has reportedly been exploited in the wild.
Affected products
- N-able N-central through 2026.3.1
Timeline
- 2026-08-02: disclosed: Initial publication by N-able
- 2026-08-02: patched: N-central 2026.3 Hotfix 1 released
- 2026-08-03: advisory: NVD publication date
- 2026-08-03: exploited: Reported as exploited in the wild in advisory metadata