CVE-2026-86206
Received Received - Intake

Unauthorized API Access in N-central

Vulnerability report for CVE-2026-86206, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: N-able

Description

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-06
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
n-able n-central to 2026.3_hf3 (inc)
n-able n-central 2026.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-791 The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in the N-central internal API access control filter that allows unauthorized access to internal APIs. It is fixed in versions N-central 2026.3 HF3 and 2026.4.

Detection Guidance

The provided CVE data does not include specific detection methods or commands for identifying this vulnerability on a network or system. The vulnerability is addressed by upgrading to N-central 2026.3 HF3 or 2026.4.

Impact Analysis

An attacker could exploit this to bypass authentication and gain full access to the N-central platform. Unpatched systems are at risk, though no confirmed exploitations have been reported yet.

Compliance Impact

The vulnerability allows unauthorized access to internal APIs, which could lead to data breaches or unauthorized data exposure. This may impact compliance with standards like GDPR and HIPAA by increasing the risk of unauthorized data access or disclosure, potentially violating data protection requirements.

Mitigation Strategies

Upgrade to N-central 2026.3 HF3 or 2026.4 immediately to address the vulnerability. Hosted instances are already patched. No agent updates are required for protection, but upgrading agents is recommended as a best practice.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86206. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart