CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

Imported from official source

Cybersecurity Classified by Officially

While conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server. Semicolon/Forwarded access-control bypass UserTwoFactorLogin authentication bypass Both CVE-2026-86206 and CVE-2026-86207 have been patched by the vendor via N-central 2026.3 Hotfix 3. N-able N-central is an enterprise-grade Remote Monitoring and Management (RMM) platform designed for Managed Service Providers (MSPs) and IT departments to monitor, manage, and secure complex, large-scale networks from a centralized dashboard. These vulnerabilities were discovered by Stephen Fewer, Senior Principal Security Researcher at Rapid7, and are being disclosed in accordance with Rapid7's vulnerability disclosure policy. N-central exposes its management interface (TCP 8443 by default) through Envoy, an edge proxy. Envoy passes accepted requests to Jetty, the Java web server that hosts N-centra...

Read the original at the source: https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed

Officially imported this from Rapid7’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on

Provenance

Organization
Rapid7 — imported from official source
Official source
https://blog.rapid7.com/rss/ RSS
Imported
September 18, 2026 11:35
Versions
2 recorded
Identity
blt70b071a4b09e549f

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.