CVE-2026-18577
N-central Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that results from an incomplete patch for the previously disclosed CVE-2026-18556. It allows unauthenticated remote attackers to bypass authentication mechanisms and take over user accounts, including administrative accounts, on affected N-central instances. The vulnerability affects N-central versions through 2026.3.1, with version 2026.3.1.7 confirmed as unaffected. It was published on August 2, 2026, and carries a CVSS v4.0 base score of 8.2 (High), assigned by N-able (GitHub Advisory, CISA KEV).

Détails techniques

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the product requires authentication but exposes an alternate path or channel that does not enforce it (GitHub Advisory). The original patch for CVE-2026-18556 failed to address all authentication bypass vectors, leaving an alternate code path exploitable by unauthenticated network attackers. Exploitation requires no privileges, no user interaction, and no special attack requirements, though attack complexity is rated High, suggesting some non-trivial conditions must be met (e.g., specific request crafting or timing). Security researchers have described the flaw as granting attackers "god mode" access to the N-central RMM console (ixuvo.com, ThreatLocker Blog).

Impact

Successful exploitation allows an unauthenticated attacker to fully take over N-central administrative accounts, gaining unrestricted access to the RMM (Remote Monitoring and Management) console. Because N-central is used by Managed Service Providers (MSPs) to manage customer endpoints, a compromised N-central server can serve as a pivot point for supply-chain-style attacks against all managed customer environments — enabling lateral movement, data exfiltration, ransomware deployment, and persistent access across potentially thousands of downstream endpoints (BleepingComputer, Dark Reading, Decryption Digest).

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing N-able N-central instances running versions at or below 2026.3.1 using tools like Shodan or Censys, targeting the N-central web management interface (typically exposed on TCP 443).
  2. Identify alternate authentication path: Analyze the N-central web application for endpoints or API routes that were not covered by the CVE-2026-18556 patch — specifically alternate paths or channels that bypass the primary authentication enforcement logic (CWE-288).
  3. Craft bypass request: Send a specially crafted HTTP request to the identified alternate endpoint, exploiting the incomplete patch to circumvent authentication checks without supplying valid credentials.
  4. Achieve account takeover: Upon successful bypass, gain access to an administrative or privileged N-central account session, effectively obtaining full control of the RMM console (described by researchers as "god mode" access).
  5. Lateral movement to managed endpoints: Leverage N-central's built-in remote management capabilities (script execution, agent deployment, remote desktop) to push malicious payloads, establish persistence, or exfiltrate data across all customer-managed endpoints (BleepingComputer, ixuvo.com, Dark Reading).

Indicateurs de compromis

  • Network: Unexpected authentication or session establishment events originating from Mullvad VPN exit nodes or other anonymizing infrastructure targeting the N-central web interface; unusual inbound requests to alternate API endpoints not typically accessed in normal operations (cybersecurityboard.com).
  • Logs: N-central access logs showing successful logins or session creation without corresponding valid credential entries; authentication events from unexpected IP addresses or geographic locations; audit log entries for administrative actions (script deployment, agent installation) not initiated by known administrators.
  • File System: Unexpected scripts, agents, or executables deployed to managed endpoints via N-central automation; new scheduled tasks or services created on managed endpoints consistent with attacker tooling.
  • Process: Unusual processes spawned on managed endpoints originating from N-central agent processes; evidence of lateral tool transfer or reconnaissance activity (e.g., network scanning, credential dumping) on endpoints managed by N-central.
  • Account Activity: New administrative accounts created in N-central; modification of existing admin account credentials or MFA settings; unexpected API key generation within the N-central console (BleepingComputer, Arctic Wolf).

Atténuation et solutions de contournement

N-able released N-central version 2026.3.1.7 (Hotfix 1) as the patched release, which addresses the incomplete fix for CVE-2026-18556 (N-able Status, N-able Release Notes). All organizations running N-central versions through 2026.3.1 should upgrade to 2026.3.1.7 immediately. CISA's BOD 22-01 requires federal agencies to remediate this vulnerability by August 6, 2026, and recommends all organizations treat this as a critical priority given active exploitation; if patching is not immediately possible, CISA advises following BOD 26-04 guidance or discontinuing use of the product (CISA KEV). Additionally, organizations should review N-central audit logs for signs of unauthorized access and conduct forensic triage per CISA's guidance.

Réactions de la communauté

N-able publicly acknowledged the active exploitation and confirmed that attackers successfully reached managed customer endpoints, characterizing the situation as serious (BleepingComputer, The Hacker News). Security researchers and the community widely described the flaw as granting "god mode" access to MSP infrastructure, with significant concern expressed about the supply-chain implications for downstream managed customers (ThreatLocker Blog, GovInfoSecurity). Arctic Wolf and RedLegg published detailed advisories urging immediate patching, and the story received broad coverage across major security outlets including Dark Reading, BleepingComputer, The Hacker News, and SC World (Arctic Wolf, RedLegg, Dark Reading). Social media discussion on Reddit, Mastodon, and LinkedIn was active, with MSP community members expressing urgency and frustration over the incomplete initial patch (Reddit r/Nable).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté N-central Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2025-11367CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NonOuiNov 12, 2025
CVE-2025-11700HIGH8.4
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NonOuiNov 12, 2025
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
OuiOuiAug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
OuiOuiAug 01, 2026
CVE-2025-9316MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NonOuiNov 12, 2025

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités