Wiz가 Google Cloud에 합류: 함께 마법을 만드는 것

CVE-2026-18556
N-central 취약성 분석 및 완화

개요

CVE-2026-18556 is an authentication bypass vulnerability (CWE-288) in N-able N-central, a widely used remote monitoring and management (RMM) platform for managed service providers (MSPs). The flaw allows unauthenticated network attackers to circumvent authentication mechanisms via an alternate path or channel, potentially gaining administrative access to the platform. All N-central versions through 2026.1 are affected. The vulnerability was published on August 1, 2026, and has a CVSS v3.1 base score of 7.4 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, CISA KEV).

기술적 세부 사항

The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning N-central's authentication logic can be bypassed by accessing an alternate path or channel that does not enforce the standard authentication controls. The attack vector is network-based, requires no privileges or user interaction, and has high attack complexity — suggesting that exploitation requires specific conditions or knowledge of the alternate path. No user interaction is required, and the vulnerability is exploitable remotely without authentication. Technical write-ups from Rapid7 and Arctic Wolf have analyzed the flaw in the context of its companion vulnerability CVE-2026-18577, noting that the initial patch for CVE-2026-18556 was incomplete and left an alternate bypass path open (Rapid7, Arctic Wolf).

영향

Successful exploitation allows an unauthenticated attacker to gain administrative access to the N-central RMM console — described by researchers as "god mode" access — enabling them to read sensitive data and modify system configuration. Because N-central is used by MSPs to manage endpoints across multiple client organizations, a compromised N-central instance can serve as a pivot point for supply-chain-style attacks against all managed endpoints. N-able confirmed that attackers were able to reach managed endpoints via the flaw, and China-linked threat actors (Storm-1175) have been reported deploying StormEncryptor ransomware through this access path (CISA KEV, Arctic Wolf, N-able Blog).

악용 가능성

CVE-2026-18556 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 4, 2026, with a due date of August 7, 2026 for federal agencies to remediate (CISA KEV). The EPSS score is approximately 0.27–0.49%, though real-world exploitation has been confirmed. A defensive IOC triage toolkit (not an exploit) was published on GitHub by CreamyG31337 to help defenders detect post-exploitation artifacts (GitHub IOC Toolkit). China-linked threat group Storm-1175 has been attributed to attacks leveraging this vulnerability to deploy StormEncryptor ransomware. The NVD SSVC assessment classifies exploitation as "active" and the vulnerability as "automatable" (Rescana, N-able Blog).

착취 단계

  1. Reconnaissance: Identify internet-facing N-central instances using tools like Shodan or Censys, targeting versions through 2026.1. N-central is commonly exposed on standard HTTPS ports.
  2. Identify alternate authentication path: Probe the N-central web interface for endpoints or API paths that bypass the primary authentication mechanism — the vulnerability involves an alternate channel that does not enforce standard login controls (CWE-288).
  3. Send unauthenticated request: Craft an HTTP request targeting the alternate path or channel that bypasses authentication, exploiting the incomplete enforcement of access controls.
  4. Gain administrative access: Upon successful bypass, the attacker obtains administrative-level access to the N-central console without valid credentials, enabling full control of the RMM platform.
  5. Lateral movement to managed endpoints: Use N-central's built-in agent management capabilities to push scripts, commands, or malware (e.g., ransomware) to all managed endpoints across MSP client organizations, achieving broad supply-chain compromise (Arctic Wolf, Rapid7).

타협의 징후

  • Network: Unexpected or anomalous HTTP requests to N-central web endpoints from unknown external IP addresses, particularly to authentication-adjacent API paths; outbound connections from the N-central server to unknown infrastructure.
  • Logs: N-central access logs showing successful administrative sessions with no corresponding valid login event; authentication log entries reflecting access via alternate paths or channels; unusual administrative actions (policy changes, agent deployments) in audit logs.
  • File System: Unexpected scripts, executables, or agent packages staged on the N-central server or pushed to managed endpoints; presence of StormEncryptor ransomware artifacts on managed systems.
  • Process: Unusual processes spawned by the N-central service account; RMM agent activity on managed endpoints initiating unexpected commands or downloading payloads.
  • Behavioral: New administrative accounts created in N-central without authorization; bulk deployment of scripts or software to managed endpoints outside of normal change windows (GitHub IOC Toolkit, Arctic Wolf).

완화 및 해결 방법

N-able released a security update addressing CVE-2026-18556 and the related CVE-2026-18577 on August 2, 2026, followed by a second hotfix (Hotfix 2) as attackers continued to exploit an incomplete initial patch. Organizations should update N-central to a version beyond 2026.1 immediately, applying all available hotfixes as described in N-able's security update blog posts (N-able Blog). CISA directed federal agencies to remediate by August 7, 2026, per BOD 26-04 guidance. As interim measures, organizations should restrict internet exposure of N-central, monitor for unauthorized administrative sessions, review audit logs for suspicious activity, and verify the integrity of managed endpoint deployments (CISA KEV).

커뮤니티 반응

The vulnerability generated significant attention across the security community given N-central's role as a critical MSP management platform. Researchers at Arctic Wolf, Rapid7, ThreatLocker, Field Effect, and eSentire all published advisories and analyses, with ThreatLocker describing the flaw as granting attackers "god mode" access to the RMM console (Arctic Wolf, Rapid7). The Hacker News, SecurityWeek, BleepingComputer, and GovInfoSecurity covered the story extensively, with GovInfoSecurity characterizing the flaw as a "worst-case scenario" for MSPs. The Water ISAC issued a TLP:CLEAR vulnerability notification, and Canada's CCCS published a security advisory. Community discussion on Reddit and Mastodon highlighted urgency around patching, and the incomplete initial patch drew criticism, with one blog post titled "Three fixes shipped in six days, none of them made the thing safe." China-linked threat actor attribution (Storm-1175/StormEncryptor ransomware) further elevated the severity of community response (SecurityWeek, BleepingComputer).

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 N-central 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-86218CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Sep 06, 2026
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Aug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Aug 01, 2026
CVE-2026-86207HIGH7.7
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
아니요Sep 05, 2026
CVE-2026-86206MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
아니요Sep 05, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자