CVE-2026-18577 – N-able N-central
“An incomplete fix can leave the door just as open as the original flaw.”
This patch addresses CVE-2026-18577, an authentication bypass vulnerability (CWE-288) affecting N-able N-central through version 2026.3.1. The CVSS score is 8.2, which is High severity. No verified real-world exploitation has been reported.
The vulnerability results from an incomplete fix for CVE-2026-18556, allowing an attacker to bypass authentication and potentially take over user accounts on affected systems. While the vulnerability is not identified as Remote Code Execution (RCE), it has Elevation of Privilege (EoP) characteristics because successful exploitation can lead to unauthorized account access and control. Organizations running affected versions of N-central should apply the latest available update to fully remediate the issue.
Key Details
- Affected Product
- N-able N-central
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-288