CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)
OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE…
KEV ✓ EPSS 0.54 CVE-2026-18577 CVE-2026-86206 CVE-2026-86207 N-able US