CVE-2026-86206: N-able N-central

Medium severity, CVSS 6.9. EPSS: 1.1% chance of exploitation in the next 30 days.

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

Affected products

  • N-able N-central: before 2026.3.1.13 (fixed in 2026.3.1.13)

Published 2026-09-05. Last modified 2026-09-08.