
PEACH
Un cadre d’isolation des locataires
CVE-2026-86206 is an authorization bypass vulnerability in N-able N-central's internal API access control filter that allows unauthenticated attackers to access restricted internal APIs. It affects N-central versions prior to 2026.3.1.13 and was disclosed on September 5, 2026. The vulnerability is classified as Moderate severity with a CVSS v4.0 base score of 6.9 (GitHub Advisory, ENISA EUVD). Patches are available in N-central 2026.3 HF3 and 2026.4 (N-able Status).
The root cause is classified as CWE-791 (Incomplete Filtering of Special Elements), meaning the access control filter in N-central's internal API layer does not completely validate or filter request elements, allowing crafted requests to bypass authorization checks. The attack vector is network-based, requires no privileges, no user interaction, and no special attack requirements, making it exploitable by any unauthenticated remote attacker who can reach the N-central management interface. The vulnerability specifically targets the internal API access control filter, enabling unauthorized access to API endpoints that should be restricted to authenticated or privileged users (GitHub Advisory, ENISA EUVD).
Successful exploitation allows an unauthenticated attacker to bypass access controls and reach internal N-central APIs, potentially exposing sensitive management functionality and data within the platform. The primary impact is a low confidentiality breach on the vulnerable system, with no direct integrity or availability impact scored. However, given that N-central is an IT management platform used by MSPs to manage customer environments, unauthorized API access could expose managed device data, credentials, or configuration information, with potential for broader downstream impact across managed endpoints (GitHub Advisory, ENISA EUVD).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.
N-able has released patches addressing this vulnerability in N-central 2026.3 HF3 (version 2026.3.1.13) and N-central 2026.4. Organizations should upgrade to one of these versions as the primary remediation (N-able Status, N-able Release Notes). As a temporary workaround if immediate patching is not feasible, restrict network access to the N-central management interface at the firewall or network perimeter level to limit exposure of internal API endpoints to trusted networks only. Additionally, monitor API access logs for suspicious unauthenticated activity targeting internal endpoints.
The MSP and sysadmin communities responded promptly on Reddit, with threads in r/msp, r/sysadmin, and r/Nable flagging the hotfix as urgent and discussing patching timelines (Reddit r/msp, Reddit r/sysadmin). N-able published an official blog post and security advisory on the same day as disclosure, indicating proactive vendor communication (N-able Blog). The vulnerability was disclosed alongside CVE-2026-86207, which was also addressed in the same hotfix, drawing additional attention from the MSP community.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."