Description
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
Published: 2026-09-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the N‑central internal API access control filter permits an unauthorised party to invoke internal APIs that are otherwise protected. The flaw effectively bypasses the intended authorization checks, allowing leakage or manipulation of data exposed by those APIs. This weakness corresponds to CWE‑791 and provides a path for non‑privileged users to access sensitive system functions.

Affected Systems

Systems affected are those running N‑central by N‑Able. The issue exists in versions released before the 2026.3 HF3 update and before the 2026.4 release, for which the fix applies. Administrators should verify the installed version and ensure it is at least 2026.3 HF3 or 2026.4 to remove the vulnerability.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity, and the EPSS score is not available, so the precise likelihood of exploitation is unknown. The vulnerability is not included in CISA’s KEV catalog. Attackers can potentially exploit the bypass through internal network traffic or by sending crafted requests to the API endpoints; the exact attack vector is inferred from the description, as it is an internal API filter bypass.

Generated by OpenCVE AI on September 5, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade N‑central to version 2026.3 HF3 or later, which contains the access control filter fix.
  • Restrict API access to trusted IP ranges and enforce authentication on all internal API endpoints.
  • Conduct a vulnerability scan to identify any exposed internal APIs and verify that the filter is active.

Generated by OpenCVE AI on September 5, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared N-able
N-able n-central
Vendors & Products N-able
N-able n-central

Sat, 05 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
Title Access control filter bypass allows unauthorised access to APIs
Weaknesses CWE-791
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

N-able N-central
cve-icon MITRE

Status: PUBLISHED

Assigner: N-able

Published:

Updated: 2026-09-05T19:19:47.225Z

Reserved: 2026-09-05T12:27:20.554Z

Link: CVE-2026-86206

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T20:17:18.833

Modified: 2026-09-05T20:17:18.833

Link: CVE-2026-86206

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T20:30:17Z

Weaknesses
  • CWE-791

    Incomplete Filtering of Special Elements