CVE-2026-86207: Authentication bypass leads to unauthorised access to N-central
Published Sep 5, 2026
·Updated
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
Affected Software
1 affected component
N-able N-Central<2026.3 HF 3
Event History
Sep 5, 2026
CVE Published
via MITRE·07:12 PM
Data Sourced
via MITRE·07:12 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
N-able N-central versions earlier than 2026.3 HF 3 are affected. The issue is described as affecting internal-only APIs.
2
What access could an attacker gain?
The vulnerability can allow authentication bypass and unauthorised access to N-central through affected internal-only APIs.
3
What version remediates the issue?
Upgrade N-central to 2026.3 HF 3 or a later version.