Unauthenticated administrative account takeover
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
N-able N-central has a vulnerability that allows attackers to take over admin accounts without needing a password, by using an alternate way to access the system. This is critical because admins control everything, so attackers could steal data or damage the entire network.
An authentication bypass vulnerability in N-able N-central (versions through 2026.1) exists in alternate authentication paths or channels, enabling unauthenticated attackers to assume administrative privileges. The vulnerability allows complete administrative account takeover without credentials, granting full system access and control capabilities.