www.rapid7.com 8 Sept 2026, 11:01 UTC

N-able N-central Flaws Let Attackers Create Admin Accounts Remotely

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

RAPID 7 has disclosed two authentication bypass vulnerabilities in N-able N-central, tracked as CVE-2026-86206 (Semicolon/Forwarded access-control bypass) and CVE-2026-86207 (UserTwoFactorLogin authentication bypass). When chained, these flaws could let a remote unauthenticated attacker create a new attacker-controlled System administrator account on an affected N-central server.

Rapid7’s analysis shows the issues arise in how Envoy, Jetty and N-central’s access filters evaluate requests that include a semicolon in the path and a crafted Forwarded header, enabling a local-style request to reach protected SOAP interfaces. CVE-86206 exploits a mismatch between Envoy’s path checks and Jetty’s decoding, while CVE-86207 leverages a separate flaw in the legacy two-factor flow to convert a pre-login session into an authenticated one.

Rapid7 provides technical detail and an exploit context, noting that an attacker would still need to bypass local request protections after gaining the initial bypass.

N-able responded with a fix in N-central 2026.3 Hotfix 3 (version 2026.3.1.13). The vendor states that all versions prior to 2026.3.1.13 are vulnerable, and that customers with on‑premise N-central should apply the update urgently. Hosted N-central customers do not need to take action, as the vendor has already applied the fix. The vulnerabilities were discovered by Stephen Fewer of Rapid7, who coordinated disclosure under Rapid7’s policy.

The article notes that Rapid7 is enabling exposure checks for affected products via their vulnerability platforms. The disclosures also refer to prior related work on N-central authentication bypasses, and outline the remediation path via N-central 2026.3 HF3. 8 September 2026.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline