{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-86218",
  "revision": 1,
  "title": "N-able N-central — Pre-Authentication Code Injection to RCE",
  "summary": "N-able's N-central remote monitoring platform lets an unauthenticated attacker inject code that the server then runs, giving full remote code execution before any login. Versions before 2026.3.1.14 are affected and it is being exploited in the wild.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.07494,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-09-08",
    "prerequisites": "Network access to the N-central server; no account or user interaction needed"
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "N-central 2026.3.1.14"
    ]
  },
  "mitre_attack": [
    "T1190",
    "T1059"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade N-central to 2026.3.1.14 or later now; restrict internet exposure of the server until patched and triage it for signs of compromise.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-86218",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-86218",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-86218",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "title",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-86218",
      "retrieved_at": "2026-09-20T11:09:51.520Z",
      "confidence": "high",
      "extractor": "human"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86218",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution"
    }
  ],
  "published_at": "2026-09-06T03:17:17.373Z",
  "issued_at": "2026-09-20T10:52:56.734Z",
  "tags": [
    "n-able",
    "n-central",
    "code-injection",
    "rce",
    "rmm"
  ]
}
