VulDB • 5h
N-able N-central: Critical Pre-Authentication RCE CVE-2026-86218
CVE-2026-86218 is a critical pre-authentication remote code execution (RCE) vulnerability in the N-able N-central management platform. The flaw stems from a static code injection vulnerability (CWE-94 and CWE-95) located within specific HTTP endpoints, allowing unauthenticated attackers to execute arbitrary code on the host system. Because N-central serves as a centralized management hub for Managed Service Providers (MSPs), this vulnerability introduces extreme supply chain risk. Successful exploitation allows attackers to bypass authentication to gain initial access, facilitating lateral movement and the potential mass compromise of hundreds of downstream managed client environments through a single N-central instance.
Links:VulDB, techjacksolutions.com, gbhackers.com, Ionix, Huntress, Dfs, Status, Reddit, Bleepingcomputer, Cvefeed, N-able •