CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)
Cybersecurity Classified by Officially
While conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server. Semicolon/Forwarded access-control bypass UserTwoFactorLogin authentication bypass Both CVE-2026-86206 and CVE-2026-86207 have been patched by the vendor via N-central 2026.3 Hotfix 3. N-able N-central is an enterprise-grade Remote Monitoring and Management (RMM) platform designed for Managed Service Providers (MSPs) and IT departments to monitor, manage, and secure complex, large-scale networks from a centralized dashboard. These vulnerabilities were discovered by Stephen Fewer, Senior Principal Security Researcher at Rapid7, and are being disclosed in accordance with Rapid7's vulnerability disclosure policy. N-central exposes its management interface (TCP 8443 by default) through Envoy, an edge proxy. Envoy passes accepted requests to Jetty, the Java web server that hosts N-centra...
Read the original at the source: https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed
Officially imported this from Rapid7’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on
Provenance
- Organization
- Rapid7 — imported from official source
- Official source
- https://blog.rapid7.com/rss/ RSS
- Imported
- September 18, 2026 11:35
- Versions
- 2 recorded
- Identity
blt70b071a4b09e549f