Executive brief
N-central is a cloud management platform used by managed service providers to monitor and manage customer networks and systems. A flaw in the platform's internal API access controls allows attackers to bypass authentication and gain unauthorized access to internal APIs, potentially granting full administrative control over the platform and all monitored customer environments.
Technical details
A vulnerability in N-central's internal API access control filter fails to properly validate requests, allowing attackers to bypass authentication mechanisms and access internal APIs without valid credentials. The attack is network-accessible and requires no prior authentication or user interaction. An attacker exploiting this flaw can gain unauthorized access to sensitive internal APIs and potentially achieve full control of the N-central platform. The vulnerability is fixed in N-central 2026.3 HF3 (build 2026.3.1.13) and 2026.4. Hosted N-central instances (NCOD) have already been patched; on-premises deployments must upgrade immediately.
Affected products
- N-able N-central Before 2026.3 HF3 and 2026.4
Timeline
- 2026-09-05: disclosed: Published on NVD
- 2026-09-05: patched: Fixed in N-central 2026.3 HF3 (2026.3.1.13) and 2026.4