Search
Find merged stories by title or summary.
CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)
Overview While conducting research into a recent N-able N-central authentication bypass vulnerability ( CVE-2026-18577 ), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server. CVE ID Description CWE CVSSv4 CVE-2026-86206 Semicolon/Forwarded access-control bypass
CVE-2026-86206 - Access control filter bypass allows unauthorised access to APIs
CVE ID : CVE-2026-86206 Published : Sept. 5, 2026, 8:17 p. m. • 27 minutes ago Description : A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026. 3 HF3 and 2026. 4 Severity: 6.9 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
You've reached the end of current stories for this search.
