Impact
The vulnerability is an incomplete patch for a prior authentication bypass flaw, allowing attackers to authenticate without valid credentials and assume administrative privileges on N‑central. This leads to full control over the system, including configuration changes, data exfiltration, and potential lateral movement within the organization. The weakness is classified as CWE‑288, which reflects an authorization bypass or privilege escalation.
Affected Systems
Vendors: N‑able. Product: N‑central. Affected versions include all releases up to and including version 2026.3.1, as the incomplete patch for the earlier CVE‑2026-18556 remains unaddressed in those builds.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity and the vulnerability grants a high‑impact privilege escalation if exploited. The EPSS score of 4% indicates a low to moderate exploitation probability, so the precise likelihood of exploitation cannot be quantified, but the KEV listing indicates that the vulnerability has been observed in the wild or is actively exploited. Based on the description of an authentication bypass, the likely attack vector is remote, though the credentials required and the exact prerequisites are not detailed in the public release.
OpenCVE Enrichment