@harrysintonen@infosec.exchange
Post #4352100
2026-08-03 10:48 UTC
Some time ago I discovered a meddled in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:
https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
#nablencentral #CVE_2026_18577 #infosec #cybersecurity
Replies (1)
-
@harrysintonen@infosec.exchange 2026-08-03 10:49
Here's my older mitm-to-SYSTEM vulnerability writeup for anyone interested: https://sintonen.fi/advisories/n-able-ecosystem-agent-improper-certificate-validation.txt N-able dismissed this as low level finding.