CVE-2026-18556
N-central 脆弱性の分析と軽減

概要

CVE-2026-18556 is an authentication bypass vulnerability (CWE-288) in N-able N-central that allows unauthenticated remote attackers to bypass authentication via an alternate path or channel. It affects all N-central versions through 2026.1 and was disclosed on August 1, 2026. The vulnerability carries a CVSS v4.0 base score of 8.2 (High), with high confidentiality impact on the vulnerable system (GitHub Advisory, Feedly). CVE-2026-18556 is closely related to a companion vulnerability, CVE-2026-18577, which represents an incomplete patch bypass that attackers exploited after the initial fix was released (Arctic Wolf, Rescana).

技術的な詳細

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning N-central exposes an alternate path or endpoint that does not enforce the same authentication controls as the primary interface. Exploitation requires no privileges, no user interaction, and no special deployment conditions (Attack Requirements: None), though attack complexity is rated High, suggesting some non-trivial precondition or environmental factor is involved. The initial patch for CVE-2026-18556 was found to be incomplete, leaving an alternate bypass path that was subsequently exploited as CVE-2026-18577, indicating the authentication enforcement gap was not fully remediated in the first fix (GitHub Advisory, dev.to, Rescana).

影響

Successful exploitation allows unauthenticated attackers to gain unauthorized access to the N-central RMM (Remote Monitoring and Management) console, described by researchers as achieving "god mode" administrative access (Cryptika, ThreatLocker). Because N-central is used by Managed Service Providers (MSPs) to manage thousands of customer endpoints, a compromised N-central instance can serve as a pivot point for supply-chain-style attacks against all managed endpoints downstream. N-able confirmed that attackers reached managed customer endpoints via the flaw, representing a worst-case scenario for MSP environments (Daily Security Review, GovInfoSecurity).

エクスプロイト可能性

CVE-2026-18556 has been actively exploited in the wild, with exploitation confirmed by multiple sources including netsecops.io and Arctic Wolf (netsecops.io, Arctic Wolf). The companion vulnerability CVE-2026-18577 (incomplete patch bypass) was added to CISA's Known Exploited Vulnerabilities (KEV) catalog, reflecting confirmed in-the-wild exploitation (The Hacker News, CISA KEV). A YouTube proof-of-concept video demonstrating exploitation has been published (YouTube PoC). The EPSS score is approximately 0.27% (19th percentile), though real-world exploitation activity significantly exceeds this model estimate (GitHub Advisory). No specific threat actor attribution has been publicly confirmed at this time.

エクスプロイテーションのステップ

  1. Reconnaissance: Identify internet-facing N-able N-central instances (versions through 2026.1) using tools like Shodan or Censys, searching for N-central web interfaces on standard ports.
  2. Identify alternate path: Probe the N-central web application for endpoints or API paths that bypass the primary authentication enforcement mechanism — the vulnerability class (CWE-288) indicates an alternate channel exists that does not require valid credentials.
  3. Send unauthenticated request: Craft and send an HTTP request directly to the alternate path or channel, bypassing the standard login flow without supplying valid credentials.
  4. Gain administrative access: The bypassed authentication grants the attacker administrative-level access to the N-central RMM console ("god mode"), enabling full control over the management platform.
  5. Lateral movement to managed endpoints: Leverage N-central's built-in remote management capabilities (script execution, agent deployment, remote access) to push malicious payloads or commands to all managed customer endpoints, enabling supply-chain-style compromise (Arctic Wolf, Rescana, ThreatLocker).

妥協の兆候

  • Network: Unexpected HTTP requests to N-central endpoints that bypass the standard authentication flow; unauthenticated sessions appearing in N-central access logs from external or unknown IP addresses; outbound connections from N-central server to unknown external hosts.
  • Logs: N-central authentication logs showing successful sessions with no corresponding valid login credential entries; access log entries for alternate or undocumented API paths without prior authentication events; admin-level actions (script deployment, agent configuration changes) with no associated authenticated user session.
  • File System: Unexpected scripts, executables, or agent packages deployed to managed endpoints originating from the N-central server; new scheduled tasks or services on managed endpoints created outside normal change windows.
  • Process: Unusual processes spawned on managed endpoints by the N-central agent (e.g., PowerShell, cmd.exe, curl) executing commands not associated with legitimate management tasks; N-central agent performing mass deployment actions across all managed devices simultaneously (Arctic Wolf, Daily Security Review).

軽減策と回避策

N-able released a security patch on August 1, 2026 addressing CVE-2026-18556, followed by a second update on August 2, 2026 to address the incomplete patch (CVE-2026-18577) (N-able Blog Aug 1, N-able Blog Aug 2). Organizations should apply the latest available patch immediately, prioritizing the August 2 update which addresses the bypass of the initial fix. As interim measures, restrict network access to N-central management interfaces to trusted IP ranges only, implement network segmentation, enable multi-factor authentication where available, and review authentication logs for signs of unauthorized access (Feedly Executive Summary, Arctic Wolf).

コミュニティの反応

The vulnerability generated significant media and community attention given its impact on MSP supply chains. The Hacker News, SecurityWeek, SC World, GovInfoSecurity, and HelpNet Security all covered the active exploitation, with GovInfoSecurity characterizing it as a "worst-case scenario" for MSPs (The Hacker News, SecurityWeek, GovInfoSecurity). ThreatLocker published a blog describing the access level as "god mode," and Arctic Wolf issued an advisory urging immediate patching (ThreatLocker, Arctic Wolf). Community discussion on Reddit and Mastodon highlighted concern over the incomplete initial patch and CISA's subsequent KEV listing of the bypass CVE-2026-18577 (Reddit).

関連情報


ソースこのレポートは AI を使用して生成されました

関連 N-central 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2025-11367CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
いいえはいNov 12, 2025
CVE-2025-11700HIGH8.4
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
いいえはいNov 12, 2025
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
はいはいAug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
はいはいAug 01, 2026
CVE-2025-9316MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
いいえはいNov 12, 2025

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者