Description
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
Published: 2026-09-05
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass exists in N-central software prior to version 2026.3 HF3, allowing attackers to gain access to internal APIs without valid credentials. This flaw can lead to unauthorized use of the system’s administrative functions, exposing sensitive configuration data and potentially enabling further compromise. The weakness is classified as improper authentication.

Affected Systems

The vulnerability affects N-able’s N-central product, all installations running a version older than 2026.3 HF3. No specific hardware or operating system constraints are noted; the issue resides entirely within the N-central application.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity. Because the EPSS score is not available, the exploitation likelihood cannot be quantified, and the vulnerability is not yet listed in the CISA KEV catalog. However, given that the bypass targets internal APIs, an attacker would need network access to the N-central management network or a foothold within that network. The implied attack vector is likely network-based, possibly via a compromised or vulnerable client that can reach the internal endpoints. A successful exploitation grants attackers authentication-equivalent privileges to the system.

Generated by OpenCVE AI on September 5, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade N-central to version 2026.3 HF3 or later
  • Confirm that all internal API endpoints enforce proper authentication and do not accept unauthenticated requests
  • Restrict network access to internal N-central APIs by applying firewall rules or network segmentation

Generated by OpenCVE AI on September 5, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared N-able
N-able n-central
Vendors & Products N-able
N-able n-central

Sat, 05 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
Title Authentication bypass leads to unauthorised access to N-central
Weaknesses CWE-305
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

N-able N-central
cve-icon MITRE

Status: PUBLISHED

Assigner: N-able

Published:

Updated: 2026-09-05T19:20:37.779Z

Reserved: 2026-09-05T12:27:21.549Z

Link: CVE-2026-86207

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T19:16:56.190

Modified: 2026-09-05T19:16:56.190

Link: CVE-2026-86207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T21:00:04Z

Weaknesses
  • CWE-305

    Authentication Bypass by Primary Weakness