CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6643

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

Rapid7 Labs discovered two chained authentication bypass vulnerabilities in N-able N-central that allow a remote unauthenticated attacker to create a new System administrator account. CVE-2026-86206 uses a semicolon in the URI path and a malformed Forwarded header to bypass Envoy proxy access controls and reach protected SOAP endpoints, while CVE-2026-86207 exploits exception handling in legacy two-factor authentication to bind a privileged user ID to a session without valid credentials. Both vulnerabilities were patched in N-central version 2026.3.1.13 released on September 5, 2026.

Why it matters: MSPs and enterprises running N-central on-premises prior to version 2026.3.1.13 are at critical risk of complete administrative takeover; immediate patching outside normal cycles is required, while hosted customers are already protected.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary