As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)
Rapid7 Labs discovered two chained authentication bypass vulnerabilities in N-able N-central that allow a remote unauthenticated attacker to create a new System administrator account. CVE-2026-86206 uses a semicolon in the URI path and a malformed Forwarded header to bypass Envoy proxy access controls and reach protected SOAP endpoints, while CVE-2026-86207 exploits exception handling in legacy two-factor authentication to bind a privileged user ID to a session without valid credentials. Both vulnerabilities were patched in N-central version 2026.3.1.13 released on September 5, 2026.
Why it matters: MSPs and enterprises running N-central on-premises prior to version 2026.3.1.13 are at critical risk of complete administrative takeover; immediate patching outside normal cycles is required, while hosted customers are already protected.
- Source published
- First seen by Cybersecurity Tracker