Attackers can hijack N-central accounts through an authentication bypass vulnerability
N-able has released an urgent hotfix for N-central to address a high-severity authentication bypass vulnerability. Attackers can potentially take over accounts in unpatched instances. Upgrade to version 2026.3.1 immediately if you are self-hosting.
Summary
A critical security flaw in N-able N-central, identified as CVE-2026-18577, allows for authentication bypass and subsequent account takeover. The vulnerability stems from an incomplete patch for a previous issue (CVE-2026-18556). N-able has released a hotfix to mitigate this risk, urging all partners to update their environments as soon as possible.
Technical details
The flaw, tracked as CVE-2026-18577, carries a CVSS score of 8.2. It affects N-central instances running versions through 2026.3. The vulnerability is tied to an incomplete patch for CVE-2026-18556, which creates a path for attackers to bypass authentication mechanisms and seize control of accounts within the platform.
While the specific technical mechanism of the bypass remains undisclosed in current documentation, N-able has confirmed that all instances not running version 2026.3.1 are vulnerable.
Affected products and fixed versions
The vulnerability impacts all N-central instances. The following table outlines the remediation path:
| Product | Vulnerable Versions | Fixed Version |
|---|---|---|
| N-able N-central | Through 2026.3 | 2026.3.1 (Hotfix) |
For users on N-central hosted instances (NCOD), the upgrade will be applied automatically by N-able. Self-hosted users must manually download and install the update via the N-able support portal.
Detection opportunities
If you suspect an instance has been compromised, N-able recommends searching for specific indicators of activity on your devices:
- File Check: Search user documents folders for a file named
svchost.exe. - Service Check: Look for a registered service named
Cloudflared. - Network Check: Review firewall logs for inbound connections from suspicious IP addresses.
If any of these indicators are found, contact N-able support and engage your internal security response team immediately.
Defender guidance
Immediate action is required for all self-hosted N-central administrators.
- Apply the Hotfix: Upgrade to build 2026.3.1.7 or higher immediately. If you are running legacy versions, follow the official upgrade path to reach a supported version before applying the hotfix.
- Agent Upgrades: While the hotfix protects the N-central server itself without requiring an agent update, you should still upgrade your agents once the server is patched to ensure all security fixes and features are active. Note that the Windows Agent installer has increased in size from 90 MB to 180 MB; plan for higher bandwidth consumption and stagger upgrades to manage network load.
- Verify MFA Capabilities: Ensure administrators can access "Reset MFA" and "Disable Two-Factor Authentication" options in the UI, as recent updates have restored these capabilities which were previously unavailable for MSP SSO users.
Sources
- https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
- https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm
- https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
- https://www.cve.org/CVERecord?id=CVE-2026-18556
