Auth Bypass via Alt Path in N-central (2026.1)
CVE-2026-18556 Published on August 1, 2026

Unauthenticated administrative account takeover
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

NVD

Known Exploited Vulnerability

This N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

The following remediation steps are recommended / required by August 7, 2026: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicab

Vulnerability Analysis

CVE-2026-18556 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. This vulnerability is known to be actively exploited by threat actors in an automatable fashion. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

Authentication Bypass Using an Alternate Path or Channel

A product requires authentication, but the product has an alternate path or channel that does not require authentication.


Products Associated with CVE-2026-18556

Want to know whenever a new CVE is published for N Able N Central? stack.watch will email you.

 

Affected Versions

N-able N-central: