← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 8, 2026 · 11:01via Rapid7 Blog

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

Brief

Overview

While conducting research into a recent N-able N-central authentication bypass vulnerability ( CVE-2026-18577 ), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.

CVE ID

Description

CWE

CVSSv4

CVE-2026-86206

Semicolon/Forwarded access-control bypass

Read more on Rapid7 Blog