CVE-2026-18577
N-central 脆弱性の分析と軽減

概要

CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that results from an incomplete patch for the previously disclosed CVE-2026-18556. It allows unauthenticated remote attackers to bypass authentication mechanisms and take over user accounts, including administrative accounts, on affected N-central instances. The vulnerability affects N-central versions through 2026.3.1, with version 2026.3.1.7 confirmed as unaffected. It was published on August 2, 2026, and carries a CVSS v4.0 base score of 8.2 (High), assigned by N-able (GitHub Advisory, CISA KEV).

技術的な詳細

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the product requires authentication but exposes an alternate path or channel that does not enforce it (GitHub Advisory). The original patch for CVE-2026-18556 failed to address all authentication bypass vectors, leaving an alternate code path exploitable by unauthenticated network attackers. Exploitation requires no privileges, no user interaction, and no special attack requirements, though attack complexity is rated High, suggesting some non-trivial conditions must be met (e.g., specific request crafting or timing). Security researchers have described the flaw as granting attackers "god mode" access to the N-central RMM console (ixuvo.com, ThreatLocker Blog).

影響

Successful exploitation allows an unauthenticated attacker to fully take over N-central administrative accounts, gaining unrestricted access to the RMM (Remote Monitoring and Management) console. Because N-central is used by Managed Service Providers (MSPs) to manage customer endpoints, a compromised N-central server can serve as a pivot point for supply-chain-style attacks against all managed customer environments — enabling lateral movement, data exfiltration, ransomware deployment, and persistent access across potentially thousands of downstream endpoints (BleepingComputer, Dark Reading, Decryption Digest).

エクスプロイト可能性

CVE-2026-18577 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026, with a remediation due date of August 6, 2026 (CISA KEV). N-able confirmed that attackers successfully took over N-central servers and reached managed customer endpoints via the flaw (BleepingComputer). Reports indicate Mullvad VPN exit nodes were observed in exploitation activity, suggesting deliberate attacker anonymization (cybersecurityboard.com). The EPSS score is approximately 1.48% (71st percentile), and no specific threat actor attribution has been publicly confirmed. No public proof-of-concept exploit code has been officially confirmed, though exploitation has been reported by multiple threat intelligence sources (GitHub Advisory, ctipilot.ch).

エクスプロイテーションのステップ

  1. Reconnaissance: Identify internet-facing N-able N-central instances running versions at or below 2026.3.1 using tools like Shodan or Censys, targeting the N-central web management interface (typically exposed on TCP 443).
  2. Identify alternate authentication path: Analyze the N-central web application for endpoints or API routes that were not covered by the CVE-2026-18556 patch — specifically alternate paths or channels that bypass the primary authentication enforcement logic (CWE-288).
  3. Craft bypass request: Send a specially crafted HTTP request to the identified alternate endpoint, exploiting the incomplete patch to circumvent authentication checks without supplying valid credentials.
  4. Achieve account takeover: Upon successful bypass, gain access to an administrative or privileged N-central account session, effectively obtaining full control of the RMM console (described by researchers as "god mode" access).
  5. Lateral movement to managed endpoints: Leverage N-central's built-in remote management capabilities (script execution, agent deployment, remote desktop) to push malicious payloads, establish persistence, or exfiltrate data across all customer-managed endpoints (BleepingComputer, ixuvo.com, Dark Reading).

妥協の兆候

  • Network: Unexpected authentication or session establishment events originating from Mullvad VPN exit nodes or other anonymizing infrastructure targeting the N-central web interface; unusual inbound requests to alternate API endpoints not typically accessed in normal operations (cybersecurityboard.com).
  • Logs: N-central access logs showing successful logins or session creation without corresponding valid credential entries; authentication events from unexpected IP addresses or geographic locations; audit log entries for administrative actions (script deployment, agent installation) not initiated by known administrators.
  • File System: Unexpected scripts, agents, or executables deployed to managed endpoints via N-central automation; new scheduled tasks or services created on managed endpoints consistent with attacker tooling.
  • Process: Unusual processes spawned on managed endpoints originating from N-central agent processes; evidence of lateral tool transfer or reconnaissance activity (e.g., network scanning, credential dumping) on endpoints managed by N-central.
  • Account Activity: New administrative accounts created in N-central; modification of existing admin account credentials or MFA settings; unexpected API key generation within the N-central console (BleepingComputer, Arctic Wolf).

軽減策と回避策

N-able released N-central version 2026.3.1.7 (Hotfix 1) as the patched release, which addresses the incomplete fix for CVE-2026-18556 (N-able Status, N-able Release Notes). All organizations running N-central versions through 2026.3.1 should upgrade to 2026.3.1.7 immediately. CISA's BOD 22-01 requires federal agencies to remediate this vulnerability by August 6, 2026, and recommends all organizations treat this as a critical priority given active exploitation; if patching is not immediately possible, CISA advises following BOD 26-04 guidance or discontinuing use of the product (CISA KEV). Additionally, organizations should review N-central audit logs for signs of unauthorized access and conduct forensic triage per CISA's guidance.

コミュニティの反応

N-able publicly acknowledged the active exploitation and confirmed that attackers successfully reached managed customer endpoints, characterizing the situation as serious (BleepingComputer, The Hacker News). Security researchers and the community widely described the flaw as granting "god mode" access to MSP infrastructure, with significant concern expressed about the supply-chain implications for downstream managed customers (ThreatLocker Blog, GovInfoSecurity). Arctic Wolf and RedLegg published detailed advisories urging immediate patching, and the story received broad coverage across major security outlets including Dark Reading, BleepingComputer, The Hacker News, and SC World (Arctic Wolf, RedLegg, Dark Reading). Social media discussion on Reddit, Mastodon, and LinkedIn was active, with MSP community members expressing urgency and frustration over the incomplete initial patch (Reddit r/Nable).

関連情報


ソースこのレポートは AI を使用して生成されました

関連 N-central 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2025-11367CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
いいえはいNov 12, 2025
CVE-2025-11700HIGH8.4
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
いいえはいNov 12, 2025
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
はいはいAug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
はいはいAug 01, 2026
CVE-2025-9316MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
いいえはいNov 12, 2025

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者