Database/Control plane, storage & DevOps

N-able N-central: Authentication bypass using an alternate path or channel on the RMM server
CVSS 7.4CVE-2026-18556Control plane, storage & DevOpsKnown exploitedcurated
Impact
Authentication bypass using an alternate path or channel on the RMM server
Who can reach it
Network (remote)
What to do
Control-plane: patch; the RMM has agent reach into every managed host
References
Related entries
- N-able N-central: Improper input validationCVE-2025-8876 · N-able N-centralHigh
- N-able N-central: Incomplete patch for CVE-2026-18556CVE-2026-18577 · N-able N-centralHigh
- N-able N-central: Deserialization of untrusted data allowing local code execution on the RMM serverCVE-2025-8875 · N-able N-centralHigh
- Jenkins TICS plugin: attacker-controlled build variables execute arbitrary commands on the build agentCVE-2026-84675 · Jenkins TICS plugin (build environment variable expansion into an OS command)High
- Sigstore cosign (verify-blob / verify-blob-attestation, legacy JSON bundle): SUPPLY CHAIN, VERIFICATION BYPASS: keylessNCVD-2026-056-sigstore-cosign-verify-blob-veri · Sigstore cosign (verify-blob / verify-blob-attestation, legacy JSON bundle)High
- Grafana: Stored XSS via Unified AlertingCVE-2022-31097 · GrafanaHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.