CVE-2026-18556: Unauthenticated administrative account takeover
Published Aug 1, 2026
·Updated
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1.
Affected Software
1 affected component
N-able N-Central<=2026.1
Event History
Aug 1, 2026
CVE Published
via MITRE·07:59 PM
Data Sourced
via MITRE·07:59 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-18556?
CVE-2026-18556 has a high severity score of 8.2.
2
What does CVE-2026-18556 affect?
CVE-2026-18556 affects N-able N-central software through version 2026.1.
3
How can I fix CVE-2026-18556?
To mitigate CVE-2026-18556, ensure you update N-able N-central to a version beyond 2026.1.
4
What type of vulnerability is CVE-2026-18556?
CVE-2026-18556 is an unauthenticated administrative account takeover vulnerability caused by authentication bypass.
5
What are the consequences of CVE-2026-18556?
Exploitation of CVE-2026-18556 allows attackers to gain unauthorized access to administrative functions within N-able N-central.