CVE-2026-86206: Access control filter bypass allows unauthorised access to APIs
Published Sep 5, 2026
·Updated
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
Affected Software
1 affected component
N-able N-Central>2026.3 HF3<2026.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
N-centralto a version that resolves this vulnerability.Fixed in 2026.3 HF3 - Upgrade
Upgrade
N-centralto a version that resolves this vulnerability.Fixed in 2026.4
Event History
Sep 5, 2026
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which releases contain the fix?
The issue is fixed in N-central 2026.3 HF3 and N-central 2026.4.
2
What type of access could an attacker gain?
The access control filter bypass can allow unauthorised access to N-central internal APIs.