← back
CVE-2026-18556highunder attackCWE-288

Unauthenticated administrative account takeover

71Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.2epss 0.5%
from disclosure to weapon5 days
Published on NVDAug 1
1st PoC+5d
CISA KEV+3d
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2026-08-07

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

N-able N-central has a vulnerability that allows attackers to take over admin accounts without needing a password, by using an alternate way to access the system. This is critical because admins control everything, so attackers could steal data or damage the entire network.

Technical detail

An authentication bypass vulnerability in N-able N-central (versions through 2026.1) exists in alternate authentication paths or channels, enabling unauthenticated attackers to assume administrative privileges. The vulnerability allows complete administrative account takeover without credentials, granting full system access and control capabilities.

Summary generated and translated by AI from the official description.
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
N-able · N-central
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.