Summary
CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central resulting from an incomplete patch for CVE-2026-18556. It allows a remote, unauthenticated attacker to bypass authentication and take over administrative accounts. The flaw is rated HIGH (CVSS 8.2) and is being actively exploited in the wild.
Technical details
- Root cause: An incomplete fix for the earlier CVE-2026-18556 authentication flaw, leaving an alternate path or channel that bypasses authentication (CWE-288).
- Trigger conditions: No privileges or user interaction required; the attack is remotely exploitable against exposed N-central servers.
- Attack vector: Network (AV:N), with high attack complexity (AC:H).
- Impact: Bypass of authentication leading to administrative account takeover of the N-central console. Because N-central is an RMM platform, a compromised server can be leveraged to reach and act on managed downstream endpoints.
Affected software
- N-able N-central versions 0 through 2026.3 (all versions prior to the hotfix, including 2026.3, across hosted and on-premises deployments).
- Fixed in N-central 2026.3.1.7 and later.
Severity
- CVSS v4.0 base score: 8.2 (HIGH)
- Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:A
Mitigation and recommended actions
- Immediate: Upgrade all N-central instances to hotfix version 2026.3.1.7 or later as soon as possible.
- Hosted (NCOD) instances: N-able notifies affected customers directly of the upgrade schedule; no customer action is required for these instances at this time.
- If patching is delayed: Restrict network exposure of the N-central management console and monitor for the indicators of compromise published by N-able, given confirmed active exploitation.

