• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-18556: authentication bypass in N-able N-central

Remote unauthenticated attackers can bypass authentication on N-able N-central, allowing access to protected functionality and sensitive data; tracked as CVE-2026-18556. The issue affects N-central through 2026.1 (2026.x branch); an attacker only needs network access to the N-central service and no valid credentials or user interaction to exploit the alternate path weakness. The underlying flaw is an authentication bypass (CWE-288) that can lead to confidentiality and integrity impact.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
7.4HIGH
EPSS
0.07882
CWE
CWE-288
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: this CVE is listed on CISA’s Known Exploited Vulnerabilities catalog with a federal remediation deadline of 2026-08-07, so prioritize mitigation immediately; public exploit code also exists, increasing immediate risk.

What is CVE-2026-18556?

Remote unauthenticated attackers can bypass authentication on N-able N-central, allowing access to protected functionality and sensitive data; tracked as CVE-2026-18556. The issue affects N-central through 2026.1 (2026.x branch); an attacker only needs network access to the N-central service and no valid credentials or user interaction to exploit the alternate path weakness. The underlying flaw is an authentication bypass (CWE-288) that can lead to confidentiality and integrity impact. The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path).

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of N-able N-central are affected?

BRANCHAFFECTEDFIXED
2026.x2026.1 and earlier

Is CVE-2026-18556 being exploited?

CISA added CVE-2026-18556 to its Known Exploited Vulnerabilities catalog on 2026-08-04, and U.S. federal agencies are required to remediate by 2026-08-07. Public exploit code is available.

How to fix CVE-2026-18556

  1. Isolate or restrict network exposure of N-central to trusted management networks and VPNs.
  2. Follow N-able’s mitigation guidance and implement any recommended configuration changes immediately.
  3. Monitor logs and authentication-related telemetry for suspicious access attempts and indicators of compromise.
  4. Follow CISA’s KEV remediation instructions, and consider discontinuing use of the product if mitigations are unavailable.

Frequently asked questions

Is CVE-2026-18556 being actively exploited?

CISA added CVE-2026-18556 to its Known Exploited Vulnerabilities catalog on 2026-08-04 and required remediation by 2026-08-07; public exploit code is also available.

Which N-central versions are affected by CVE-2026-18556?

N-able N-central versions through 2026.1 (the 2026.x branch, 2026.1 and earlier) are affected.

Is there a patch for CVE-2026-18556?

No fixed version is listed in the vendor-affected data; apply vendor mitigations and reduce exposure until a vendor patch is released.

Does CVE-2026-18556 require authentication?

No; the vulnerability is an authentication bypass that allows unauthenticated network attackers to access N-central functionality without valid credentials.

References