CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Published Aug 1, 2026
·Updated
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1.
Other sources
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
— CISA
Affected Software
3 affected components
N-able N-Central<=2026.1
N-able N-Central<=2026.1
N-able N-Central
Event History
Aug 1, 2026
CVE Published
via MITRE·07:59 PM
Data Sourced
via MITRE·07:59 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Aug 3, 2026
News Published
via Dark Reading·09:21 PM
Aug 4, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Aug 6, 2026
News Published
via Dark Reading·03:14 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-18556?
CVE-2026-18556 has a high severity score of 8.2.
2
What does CVE-2026-18556 affect?
CVE-2026-18556 affects N-able N-central software through version 2026.1.
3
How can I fix CVE-2026-18556?
To mitigate CVE-2026-18556, ensure you update N-able N-central to a version beyond 2026.1.
4
What type of vulnerability is CVE-2026-18556?
CVE-2026-18556 is an unauthenticated administrative account takeover vulnerability caused by authentication bypass.
5
What are the consequences of CVE-2026-18556?
Exploitation of CVE-2026-18556 allows attackers to gain unauthorized access to administrative functions within N-able N-central.