PT-2026-67139 · N-Central · N-Central

CVE-2026-18577

·

Published

2026-08-02

·

Updated

2026-08-03

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions N-central versions prior to 2026.3.2
Description An incomplete patch allows for authentication bypass and account takeover. This issue occurs when an attacker uses an alternate path or channel to bypass the authentication mechanism.
Recommendations Update N-central to version 2026.3.2 or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18577

Affected Products

N-Central