CODERED VTA

N – able N – central Authentication Bypass Flaws CVE – 2026 – 86206 and CVE – 2026 – 86207 Enable Unauthenticated Administrator Account Creation

High
Robot and security concept
Photo by Possessed Photography on Unsplash

Two security vulnerabilities, tracked as CVE-2026-86206 and CVE-2026-86207, have been identified in the N-able N-central Remote Monitoring and Management (RMM) platform. The vulnerabilities were discovered by Rapid7 Labs and, when chained together, can allow a remote unauthenticated attacker to bypass authentication controls and create a new attacker-controlled System administrator account on an affected N-central server. CVE-2026-86206 is an access-control bypass vulnerability rated 6.9 Medium, while CVE-2026-86207 is an authentication bypass vulnerability rated 7.7 High under CVSS v4.0.

The attack chain abuses inconsistencies in how N-central processes specially crafted HTTP requests and its legacy authentication functionality. An attacker can first exploit CVE-2026-86206 to gain access to internal API functionality that should normally be inaccessible to remote users. CVE-2026-86207 can then be leveraged through the platform's UserTwoFactorLogin functionality to convert a pre-authentication session into a privileged authenticated session. Once successfully exploited, the attacker can create a System-level administrator account and obtain extensive control over the N-central platform, presenting significant risk to organizations and Managed Service Providers that use N-central to centrally manage endpoints and customer environments.

N-able initially addressed both vulnerabilities in N-central 2026.3 Hotfix 3, build 2026.3.1.13, released on September 5, 2026. This was shortly superseded by N-central 2026.3 Hotfix 4, build 2026.3.1.14, which additionally remediates a separate critical pre-authentication remote code execution flaw, CVE-2026-86218 (CVSS v4.0 10.0); customers should therefore treat HF4 as the minimum required release. The vendor has advised customers operating on-premises N-central deployments to apply the update immediately, while hosted N-central environments have already been patched. At the time of disclosure, N-able stated it had no confirmed evidence that CVE-2026-86206, CVE-2026-86207 or CVE-2026-86218 had been exploited in production environments; however, unpatched systems remain at risk, particularly given the publication of detailed technical information describing how the vulnerabilities can be chained to achieve privileged access.

Attack Surface

System Management Service, Web Application

Tactics

Initial Access, Privilege Escalation, Persistence, Defense Evasion

Techniques

  • T1190 – Exploit Public-Facing Application
  • T1078 – Valid Accounts
  • T1136 – Create Account
  • T1098 – Account Manipulation

SuperPRO's Threat Countermeasures Procedures

  1. Immediately upgrade N-able N-central to version 2026.3 Hotfix 4 (build 2026.3.1.14) or later. Hotfix 3 originally remediated CVE-2026-86206 and CVE-2026-86207, while Hotfix 4 supersedes HF3 and should be used as the current minimum recommended release.
  2. Review all N-central user accounts for unauthorized System administrator accounts, particularly recently created accounts, unfamiliar usernames, unexpected privilege assignments, or accounts that cannot be associated with legitimate administrative activities.
  3. Restrict network access to the N-central management interface on TCP port 8443 to trusted administrative IP ranges, VPN networks, or approved management hosts using firewall rules or access control lists. Rapid7 confirms that the N-central management interface is exposed on TCP 8443 by default.
  4. Enable and centrally collect logs relating to administrative account creation and privilege changes, and forward N-central authentication and audit telemetry to the SIEM for correlation with suspicious login activity, unusual source IP addresses, and other authentication anomalies.
  5. Monitor web proxy and application logs for suspicious HTTP requests targeting N-central legacy SOAP endpoints, particularly requests involving /dms/services/ServerUI, semicolon-based URI manipulation, or malformed Forwarded headers that may indicate attempts to exploit CVE-2026-86206.
  6. Implement network segmentation around N-central infrastructure and restrict management access through approved VPN connections, privileged access workstations, or hardened jump hosts to reduce unnecessary exposure of the RMM management platform.
  7. Monitor for abnormal use of legacy SOAP authentication functionality, including unexpected requests to User.TwoFactorLogin, Session.Hello, or ServerUI2, as these components form part of the demonstrated vulnerability chain used to obtain a privileged session and create a System administrator account.
  8. Perform a retrospective compromise assessment on previously vulnerable N-central servers, reviewing account creation events, administrative sessions, SOAP/API activity, configuration changes, and remote-management actions for evidence of unauthorized access.
  9. Verify successful patch deployment across all on-premises N-central instances and confirm that no server remains on a version earlier than the current vendor-supported security release. Customers using N-able-hosted N-central environments do not need to apply the hotfix manually because N-able states that hosted environments have already been patched.

Source

Code Red Cyber / VTA – coderedcyber.ai