Description
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.

This issue affects N-central: through 2026.1.
Published: 2026-08-01
Score: 8.2 High
EPSS: < 1% Very Low
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

Authentication bypass via an alternate path or channel allows an attacker to circumvent normal authentication controls and gain administrative privileges within N‑central. The weakness, classified as CWE‑288, removes the ability of the system to reliably verify a user’s identity, enabling unauthorized control over configuration, data, and potentially the entire network infrastructure. This can result in full system compromise, data exfiltration, and denial of service if the attacker misconfigures critical settings.

Affected Systems

The vulnerability affects N‑able’s N‑central product, with all releases through version 2026.1 susceptible. The issue applies to all installations of N‑central that rely on the default authentication flow exposed over the network.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, while the EPSS score under 1% suggests low but non‑zero exploitation probability. The vulnerability is listed in the CISA KEV catalog. Based on the description, the attacker can exploit the authentication bypass remotely without needing valid credentials, typically by accessing the admin interface via a non‑authenticated request path. Successful exploitation would grant the attacker unrestricted administrative privileges.

Generated by OpenCVE AI on August 4, 2026 at 22:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a version of N‑central released after 2026.1 that addresses the authentication bypass flaw
  • Restrict access to the N‑central administrative interface to trusted IP ranges or through a VPN, using firewall or reverse proxy rules to limit exposure
  • Enable multi‑factor authentication wherever possible and configure stringent access controls; monitor login and privilege‑elevation events for suspicious activity

Generated by OpenCVE AI on August 4, 2026 at 22:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-08-04T00:00:00+00:00', 'dueDate': '2026-08-07T00:00:00+00:00'}


Tue, 04 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 01 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared N-able
N-able n-central
Vendors & Products N-able
N-able n-central

Sat, 01 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Title Unauthenticated administrative account takeover
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

N-able N-central
cve-icon MITRE

Status: PUBLISHED

Assigner: N-able

Published:

Updated: 2026-08-05T03:56:07.447Z

Reserved: 2026-08-01T11:54:51.376Z

Link: CVE-2026-18556

cve-icon Vulnrichment

Updated: 2026-08-03T16:48:53.443Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-01T20:16:37.157

Modified: 2026-08-05T05:16:46.967

Link: CVE-2026-18556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:15:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel