Wiz가 Google Cloud에 합류: 함께 마법을 만드는 것

CVE-2026-86207
N-central 취약성 분석 및 완화

개요

CVE-2026-86207 is an authentication bypass vulnerability in N-able N-central that allows attackers with low-level privileges to bypass authentication controls and gain unauthorized access to internal-only APIs. It affects all N-central versions prior to 2026.3.1.13 (N-central 2026.3 HF 3). The vulnerability was published on September 5, 2026, and a patch was released the same day. It carries a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Feedly).

기술적 세부 사항

The vulnerability is classified as CWE-305 (Authentication Bypass by Primary Weakness), meaning the authentication algorithm itself is sound but can be circumvented due to a separate underlying weakness. An attacker with low-level network access can exploit this flaw to bypass authentication mechanisms protecting internal-only API endpoints in N-central, without requiring user interaction. The attack requires some preconditions (Attack Requirements: Present in CVSS v4.0 terminology), suggesting specific deployment or execution conditions must be met, such as network reachability to the N-central management interface. Technical details were covered in a Rapid7 analysis and a chain exploitation write-up alongside related CVEs CVE-2026-86206 and CVE-2026-86218 (Rapid7 Blog, CTI Pilot).

영향

Successful exploitation allows an attacker to access internal-only APIs without valid credentials, resulting in high confidentiality, integrity, and availability impact on the vulnerable N-central system. Because N-central is a managed service provider (MSP) platform used to remotely manage customer endpoints, a compromise could enable lateral movement into downstream managed environments, potentially affecting thousands of end-customer systems. The vulnerability is particularly dangerous in the context of a three-vulnerability chain (with CVE-2026-86206 and CVE-2026-86218) that could facilitate full remote code execution (CTI Pilot, SC World).

악용 가능성

Exploitation of CVE-2026-86207 has been reported in the wild, with ctipilot.ch and other threat intelligence sources documenting active exploitation as part of a broader attack chain targeting N-central (CTI Pilot). The EPSS score is approximately 0.296% per Feedly data, though the GitHub Advisory Database lists it at 0.734% (52nd percentile). No public proof-of-concept exploit code has been confirmed, but a Nuclei detection template was submitted to ProjectDiscovery's repository and an exploit entry appeared on Sploitus, indicating community-level weaponization interest (GitHub Nuclei PR, Sploitus). The Canadian Centre for Cyber Security (CCCS) issued an advisory (AV26-885) covering this vulnerability (CCCS Advisory). CISA KEV catalog status is not confirmed in available data.

착취 단계

  1. Reconnaissance: Identify internet-facing N-central management servers using tools like Shodan or Censys, targeting instances running versions prior to 2026.3.1.13. Approximately 1,500 N-central servers were reported as internet-exposed at the time of disclosure.
  2. Obtain low-privilege access: Acquire or create a low-privilege account on the target N-central instance (e.g., via a free trial, leaked credentials, or a separate initial access vector).
  3. Identify internal API endpoints: Enumerate internal-only API endpoints on the N-central management interface that are intended to be restricted to authenticated administrative sessions.
  4. Trigger authentication bypass: Craft HTTP requests to the internal API endpoints that exploit the primary weakness underlying the authentication mechanism (CWE-305), bypassing the authentication check without requiring full administrative credentials.
  5. Access internal APIs: Successfully interact with restricted internal APIs, potentially reading sensitive configuration data, managed device credentials, or chaining with CVE-2026-86206 or CVE-2026-86218 to achieve remote code execution on the N-central server and pivot to managed endpoints (Rapid7 Blog, CTI Pilot).

타협의 징후

  • Network: Unusual HTTP requests to internal-only N-central API endpoints from low-privilege or unexpected user accounts; outbound connections from the N-central server to unknown external IPs following API access.
  • Logs: N-central access logs showing authentication attempts or successful access to internal API paths from accounts that should not have such access; anomalous API call patterns inconsistent with normal administrative workflows.
  • Process: Unexpected processes spawned by the N-central application service, particularly if chained with CVE-2026-86218 for RCE; unusual child processes or scripting interpreters launched from the N-central Java process.
  • File System: New or modified files in the N-central installation directory, including web shells or configuration changes not initiated by administrators.
  • Detection Tools: A Nuclei template for detection was submitted to ProjectDiscovery's nuclei-templates repository (GitHub Nuclei PR); an IOC toolkit specific to the N-central exploit chain is available at GitHub IOC Toolkit.

완화 및 해결 방법

N-able released a patch in N-central version 2026.3 HF 3 (version 2026.3.1.13), which addresses CVE-2026-86207. Organizations should upgrade to this version or later (HF 4 was subsequently released addressing additional vulnerabilities) immediately, given active exploitation reports (N-able Release Notes, N-able Blog). As a network-level workaround, restrict access to the N-central management interface to trusted IP ranges and implement firewall rules to prevent unauthorized external access to internal API endpoints. Monitor authentication logs for anomalous access patterns to internal APIs as a compensating control while patching is underway (CCCS Advisory).

커뮤니티 반응

The vulnerability generated significant community attention, particularly among MSP administrators on Reddit (r/msp, r/sysadmin, r/Nable), who flagged it as urgent given N-central's role in managing customer environments at scale. Security researchers noted that CVE-2026-86207 is part of a three-vulnerability chain with CVE-2026-86206 and CVE-2026-86218, the latter being a CVSS 10.0 pre-auth RCE, which amplified concern (The Hacker News, BleepingComputer). Rapid7 published a dedicated technical analysis, and SOCRadar, Field Effect, Arctic Wolf, and CSO Online all covered the vulnerability chain. The Canadian CCCS issued a formal advisory (AV26-885), and CISA reportedly set a September 11 deadline for remediation according to community reports (SC World, CSO Online).

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 N-central 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-86218CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Sep 06, 2026
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Aug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Aug 01, 2026
CVE-2026-86207HIGH7.7
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
아니요Sep 05, 2026
CVE-2026-86206MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
아니요Sep 05, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자