
[CIVN-2026-0390] Authentication Bypass Vulnerability in N-central
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Authentication Bypass Vulnerability in N-central
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
N-central versions prior to 2026.3
Overview
An authentication bypass vulnerability has been reported in N-central that could allow an attacker to bypass authentication and take over an administrative account on the targeted system.
Target Audience:
All end-user organizations and individuals using N-central.
Risk Assessment:
High risk of bypassing authentication and account takeover.
Impact Assessment:
Potential for authentication bypass and account takeover.
Description
N-able N-central is a remote monitoring and management (RMM) platform used by managed service providers (MSPs) to monitor, manage, and automate IT infrastructure.
An authentication bypass vulnerability has been reported in N-able N-central due to an incomplete patch for CVE-2026-18556, which allows authentication to be bypassed through an alternate path or channel. An attacker could exploit this vulnerability to bypass authentication and take over an administrative account on the targeted system.
Successful exploitation of this vulnerability could allow an attacker to bypass authentication and take over an administrative account on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
Vendor Information
N-able
https://www.n-able.com/products/n-central-rmm
References
https://www.cve.org/CVERecord?id=CVE-2026-18577
CVE Name
CVE-2026-18577
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpzVF8ACgkQ3jCgcSdc
ys/qiA/9GcB2qd17GMD7Ieeo3j7+kDIhP/U8LFHn8ojE8M6LYzsbjHx5CAO8FhGV
ksYnSZT5KSVSKYJPb64ri8KjB9EeXe9ESFhhgJBeX+ng9XSnqhSAr2vRPvvffLFp
gABvHTZN0LCuIFu42EARSqlviY8/09bdhQH2mmyXAVPZ3r43bjszq1RJb2b2/fJ0
QghrLKtuK4sc25TEdKgjU2mW/DKoQ4YE9ULm2x3QUh71eM+61DBBGLohmdAfqZKt
n8TwhgwLIIgIDtaiH0fd5q+8aMPvYGaJxyxEYGxLbla9ENtdaptCGUI7emT105ve
lwkjbY9qcs7DZem+i26CsTHDyoBqqDStqytb+V22H3dSfEzwVwZwrKjR6wmVPNOD
Kn5bqWwJN0ysHjsaRHjp9sZXP+dp5NMJ3iIVg9ZGfCE6pqc47WFHcFBMCx5OwyIg
at7drVdQMSOsXh5Wx86SpUxuoG7j3FLYcybzMbXegyira1uvE2R0bPSrUEb70sfV
LmbS2lNc57dAHDSa1UremDBxt/JVBgrKetg/IU0Vqy37vkTgSRPHXe09Yq/7kGcd
xocivlGuulIzvFzN2bBka2QA375/0lyXVmCbBEfi7+7VtEr4IWrlQAo+Vx2WHYS+
8wseK2K/oGMWLNl2VP7OgmwlauTwQA+nuoor6zYRSl2x99fwP00=
=Es7t
—–END PGP SIGNATURE—–


