Skip to main content
QUIETLYTIC
Vulnerability

N-able N-central Authentication Bypass (CVE-2026-86207)

CVE-2026-86207 is an authentication bypass affecting internal APIs in N-able N-central RMM software, per VulnCheck alone.

CVE-2026-86207
Threat Level
NOT YET SCORED
CVSS
—
Status
Active Exploitation
Confidence
Medium
Affected Products
N-able N-central (before 2026.3 HF3)

CVE-2026-86207 affects N-able N-central, a remote monitoring and management (RMM) platform widely used by managed service providers, in versions before 2026.3 HF3. NVD classifies it as CWE-305 (Authentication Bypass by Primary Weakness). Our source data does not carry a CVSS score for this CVE as of our ingestion. VulnCheck’s KEV feed reports the CVE as exploited, dated September 9, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-86207 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description for this CVE is brief: an authentication bypass in N-central before 2026.3 HF3 leads to unauthorized access to internal-only APIs. NVD does not name the specific authentication weakness responsible; N-able’s own security advisory, cited in NVD’s reference list, is the authoritative technical source, but our source data does not carry deeper mechanism detail from it.

Evidence and confidence

  • Medium confidence — the CWE-305 classification and the affected-version information, which trace to NVD and N-able’s own security advisory. The exploitation report traces to VulnCheck KEV alone.
  • Our source data does not carry a CVSS score, vector, or EPSS score/percentile for this CVE.

No field is in conflict between our sources. This is the second N-central CVE we’ve covered from this KEV batch, alongside CVE-2026-86206, an access-control filter bypass affecting the same internal-API surface and fixed in the same 2026.3 HF3 release — both point at internal API authorization as a weak point in this release line.

Why this matters

An authentication bypass reaching internal-only APIs on an RMM platform is a serious finding regardless of missing CVSS scoring, since N-central instances typically hold credentials and management access to every client environment they monitor. Combined with the related access-control bypass in the same release line, operators should treat both CVEs as a single upgrade priority rather than two independent low-urgency items.

Frequently Asked Questions

What is CVE-2026-86207? An authentication bypass (CWE-305) in N-able N-central before version 2026.3 HF3, leading to unauthorized access to internal-only APIs.

Is CVE-2026-86207 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 9, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? N-central 2026.3 HF3 and later, per NVD and N-able’s own security advisory.


Weakness classification and affected-version information sourced from the National Vulnerability Database record for CVE-2026-86207 and N-able’s own security advisory. Exploitation status and the September 9, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. No CVSS score or EPSS data was available in our ingestion as of this writing. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools