CVE-2026-18556
N-central Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-18556 is an authentication bypass vulnerability (CWE-288) in N-able N-central that allows unauthenticated remote attackers to bypass authentication via an alternate path or channel. It affects all N-central versions through 2026.1 and was disclosed on August 1, 2026. The vulnerability carries a CVSS v4.0 base score of 8.2 (High), with high confidentiality impact on the vulnerable system (GitHub Advisory, Feedly). CVE-2026-18556 is closely related to a companion vulnerability, CVE-2026-18577, which represents an incomplete patch bypass that attackers exploited after the initial fix was released (Arctic Wolf, Rescana).

Détails techniques

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning N-central exposes an alternate path or endpoint that does not enforce the same authentication controls as the primary interface. Exploitation requires no privileges, no user interaction, and no special deployment conditions (Attack Requirements: None), though attack complexity is rated High, suggesting some non-trivial precondition or environmental factor is involved. The initial patch for CVE-2026-18556 was found to be incomplete, leaving an alternate bypass path that was subsequently exploited as CVE-2026-18577, indicating the authentication enforcement gap was not fully remediated in the first fix (GitHub Advisory, dev.to, Rescana).

Impact

Successful exploitation allows unauthenticated attackers to gain unauthorized access to the N-central RMM (Remote Monitoring and Management) console, described by researchers as achieving "god mode" administrative access (Cryptika, ThreatLocker). Because N-central is used by Managed Service Providers (MSPs) to manage thousands of customer endpoints, a compromised N-central instance can serve as a pivot point for supply-chain-style attacks against all managed endpoints downstream. N-able confirmed that attackers reached managed customer endpoints via the flaw, representing a worst-case scenario for MSP environments (Daily Security Review, GovInfoSecurity).

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing N-able N-central instances (versions through 2026.1) using tools like Shodan or Censys, searching for N-central web interfaces on standard ports.
  2. Identify alternate path: Probe the N-central web application for endpoints or API paths that bypass the primary authentication enforcement mechanism — the vulnerability class (CWE-288) indicates an alternate channel exists that does not require valid credentials.
  3. Send unauthenticated request: Craft and send an HTTP request directly to the alternate path or channel, bypassing the standard login flow without supplying valid credentials.
  4. Gain administrative access: The bypassed authentication grants the attacker administrative-level access to the N-central RMM console ("god mode"), enabling full control over the management platform.
  5. Lateral movement to managed endpoints: Leverage N-central's built-in remote management capabilities (script execution, agent deployment, remote access) to push malicious payloads or commands to all managed customer endpoints, enabling supply-chain-style compromise (Arctic Wolf, Rescana, ThreatLocker).

Indicateurs de compromis

  • Network: Unexpected HTTP requests to N-central endpoints that bypass the standard authentication flow; unauthenticated sessions appearing in N-central access logs from external or unknown IP addresses; outbound connections from N-central server to unknown external hosts.
  • Logs: N-central authentication logs showing successful sessions with no corresponding valid login credential entries; access log entries for alternate or undocumented API paths without prior authentication events; admin-level actions (script deployment, agent configuration changes) with no associated authenticated user session.
  • File System: Unexpected scripts, executables, or agent packages deployed to managed endpoints originating from the N-central server; new scheduled tasks or services on managed endpoints created outside normal change windows.
  • Process: Unusual processes spawned on managed endpoints by the N-central agent (e.g., PowerShell, cmd.exe, curl) executing commands not associated with legitimate management tasks; N-central agent performing mass deployment actions across all managed devices simultaneously (Arctic Wolf, Daily Security Review).

Atténuation et solutions de contournement

N-able released a security patch on August 1, 2026 addressing CVE-2026-18556, followed by a second update on August 2, 2026 to address the incomplete patch (CVE-2026-18577) (N-able Blog Aug 1, N-able Blog Aug 2). Organizations should apply the latest available patch immediately, prioritizing the August 2 update which addresses the bypass of the initial fix. As interim measures, restrict network access to N-central management interfaces to trusted IP ranges only, implement network segmentation, enable multi-factor authentication where available, and review authentication logs for signs of unauthorized access (Feedly Executive Summary, Arctic Wolf).

Réactions de la communauté

The vulnerability generated significant media and community attention given its impact on MSP supply chains. The Hacker News, SecurityWeek, SC World, GovInfoSecurity, and HelpNet Security all covered the active exploitation, with GovInfoSecurity characterizing it as a "worst-case scenario" for MSPs (The Hacker News, SecurityWeek, GovInfoSecurity). ThreatLocker published a blog describing the access level as "god mode," and Arctic Wolf issued an advisory urging immediate patching (ThreatLocker, Arctic Wolf). Community discussion on Reddit and Mastodon highlighted concern over the incomplete initial patch and CISA's subsequent KEV listing of the bypass CVE-2026-18577 (Reddit).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté N-central Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2025-11367CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NonOuiNov 12, 2025
CVE-2025-11700HIGH8.4
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NonOuiNov 12, 2025
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
OuiOuiAug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
OuiOuiAug 01, 2026
CVE-2025-9316MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NonOuiNov 12, 2025

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités