Junglewise Threat Intelligence

CVE-2026-86207: N-able N-central authentication bypass in internal APIs

CVE-2026-86207 · Severity: info · Published 2026-09-05

Executive brief

N-central is a remote management platform used by IT service providers to manage customer networks and infrastructure. This authentication bypass vulnerability in internal APIs allows an attacker to gain unauthorized access to the entire N-central platform without valid credentials, potentially compromising management of all monitored customer systems and exposing sensitive infrastructure data.

Technical details

This vulnerability is an authentication bypass affecting internal-only APIs in N-central versions prior to 2026.3 HF3. The root cause and attack vector are not fully detailed in available sources, but the advisory indicates that an attacker can bypass authentication controls to gain unauthorized access to the platform. The vulnerability is remotely exploitable and affects both on-premises and hosted deployments (though hosted instances were patched before public disclosure). The fix is available in N-central 2026.3 HF3 (build 2026.3.1.13) and later; customers must upgrade on-premises instances immediately. No public exploitation has been confirmed.

Affected products

  • N-able N-central before 2026.3 HF3 (2026.3.1.13)

Timeline

  • 2026-09-05: disclosed

References

Related threats