
PEACH
Un cadre d’isolation des locataires
CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that results from an incomplete patch for the previously disclosed CVE-2026-18556. It allows unauthenticated remote attackers to bypass authentication mechanisms and take over user accounts, including administrative accounts, on affected N-central instances. The vulnerability affects N-central versions through 2026.3.1, with version 2026.3.1.7 confirmed as unaffected. It was published on August 2, 2026, and carries a CVSS v4.0 base score of 8.2 (High), assigned by N-able (GitHub Advisory, CISA KEV).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the product requires authentication but exposes an alternate path or channel that does not enforce it (GitHub Advisory). The original patch for CVE-2026-18556 failed to address all authentication bypass vectors, leaving an alternate code path exploitable by unauthenticated network attackers. Exploitation requires no privileges, no user interaction, and no special attack requirements, though attack complexity is rated High, suggesting some non-trivial conditions must be met (e.g., specific request crafting or timing). Security researchers have described the flaw as granting attackers "god mode" access to the N-central RMM console (ixuvo.com, ThreatLocker Blog).
Successful exploitation allows an unauthenticated attacker to fully take over N-central administrative accounts, gaining unrestricted access to the RMM (Remote Monitoring and Management) console. Because N-central is used by Managed Service Providers (MSPs) to manage customer endpoints, a compromised N-central server can serve as a pivot point for supply-chain-style attacks against all managed customer environments — enabling lateral movement, data exfiltration, ransomware deployment, and persistent access across potentially thousands of downstream endpoints (BleepingComputer, Dark Reading, Decryption Digest).
N-able released N-central version 2026.3.1.7 (Hotfix 1) as the patched release, which addresses the incomplete fix for CVE-2026-18556 (N-able Status, N-able Release Notes). All organizations running N-central versions through 2026.3.1 should upgrade to 2026.3.1.7 immediately. CISA's BOD 22-01 requires federal agencies to remediate this vulnerability by August 6, 2026, and recommends all organizations treat this as a critical priority given active exploitation; if patching is not immediately possible, CISA advises following BOD 26-04 guidance or discontinuing use of the product (CISA KEV). Additionally, organizations should review N-central audit logs for signs of unauthorized access and conduct forensic triage per CISA's guidance.
N-able publicly acknowledged the active exploitation and confirmed that attackers successfully reached managed customer endpoints, characterizing the situation as serious (BleepingComputer, The Hacker News). Security researchers and the community widely described the flaw as granting "god mode" access to MSP infrastructure, with significant concern expressed about the supply-chain implications for downstream managed customers (ThreatLocker Blog, GovInfoSecurity). Arctic Wolf and RedLegg published detailed advisories urging immediate patching, and the story received broad coverage across major security outlets including Dark Reading, BleepingComputer, The Hacker News, and SC World (Arctic Wolf, RedLegg, Dark Reading). Social media discussion on Reddit, Mastodon, and LinkedIn was active, with MSP community members expressing urgency and frustration over the incomplete initial patch (Reddit r/Nable).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."