
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-18556 is an authentication bypass vulnerability (CWE-288) in N-able N-central that allows unauthenticated remote attackers to bypass authentication via an alternate path or channel. It affects all N-central versions through 2026.1 and was disclosed on August 1, 2026. The vulnerability carries a CVSS v4.0 base score of 8.2 (High), with high confidentiality impact on the vulnerable system (GitHub Advisory, Feedly). CVE-2026-18556 is closely related to a companion vulnerability, CVE-2026-18577, which represents an incomplete patch bypass that attackers exploited after the initial fix was released (Arctic Wolf, Rescana).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning N-central exposes an alternate path or endpoint that does not enforce the same authentication controls as the primary interface. Exploitation requires no privileges, no user interaction, and no special deployment conditions (Attack Requirements: None), though attack complexity is rated High, suggesting some non-trivial precondition or environmental factor is involved. The initial patch for CVE-2026-18556 was found to be incomplete, leaving an alternate bypass path that was subsequently exploited as CVE-2026-18577, indicating the authentication enforcement gap was not fully remediated in the first fix (GitHub Advisory, dev.to, Rescana).
Successful exploitation allows unauthenticated attackers to gain unauthorized access to the N-central RMM (Remote Monitoring and Management) console, described by researchers as achieving "god mode" administrative access (Cryptika, ThreatLocker). Because N-central is used by Managed Service Providers (MSPs) to manage thousands of customer endpoints, a compromised N-central instance can serve as a pivot point for supply-chain-style attacks against all managed endpoints downstream. N-able confirmed that attackers reached managed customer endpoints via the flaw, representing a worst-case scenario for MSP environments (Daily Security Review, GovInfoSecurity).
CVE-2026-18556 has been actively exploited in the wild, with exploitation confirmed by multiple sources including netsecops.io and Arctic Wolf (netsecops.io, Arctic Wolf). The companion vulnerability CVE-2026-18577 (incomplete patch bypass) was added to CISA's Known Exploited Vulnerabilities (KEV) catalog, reflecting confirmed in-the-wild exploitation (The Hacker News, CISA KEV). A YouTube proof-of-concept video demonstrating exploitation has been published (YouTube PoC). The EPSS score is approximately 0.27% (19th percentile), though real-world exploitation activity significantly exceeds this model estimate (GitHub Advisory). No specific threat actor attribution has been publicly confirmed at this time.
N-able released a security patch on August 1, 2026 addressing CVE-2026-18556, followed by a second update on August 2, 2026 to address the incomplete patch (CVE-2026-18577) (N-able Blog Aug 1, N-able Blog Aug 2). Organizations should apply the latest available patch immediately, prioritizing the August 2 update which addresses the bypass of the initial fix. As interim measures, restrict network access to N-central management interfaces to trusted IP ranges only, implement network segmentation, enable multi-factor authentication where available, and review authentication logs for signs of unauthorized access (Feedly Executive Summary, Arctic Wolf).
The vulnerability generated significant media and community attention given its impact on MSP supply chains. The Hacker News, SecurityWeek, SC World, GovInfoSecurity, and HelpNet Security all covered the active exploitation, with GovInfoSecurity characterizing it as a "worst-case scenario" for MSPs (The Hacker News, SecurityWeek, GovInfoSecurity). ThreatLocker published a blog describing the access level as "god mode," and Arctic Wolf issued an advisory urging immediate patching (ThreatLocker, Arctic Wolf). Community discussion on Reddit and Mastodon highlighted concern over the incomplete initial patch and CISA's subsequent KEV listing of the bypass CVE-2026-18577 (Reddit).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"