{"id":23943,"date":"2026-09-18T09:00:00","date_gmt":"2026-09-18T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=23943"},"modified":"2026-09-24T09:49:00","modified_gmt":"2026-09-24T09:49:00","slug":"n-central-remains-vulnerable-to-remote-takeover-without-a-patch","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/09\/18\/n-central-remains-vulnerable-to-remote-takeover-without-a-patch\/","title":{"rendered":"N-central: Remote takeover possible without a patch"},"content":{"rendered":"<p class=\"evm-ai-translation-notice\" style=\"font-style:italic;color:#868e96;margin:0 0 24px;\">This article is an AI-generated translation of the German original. The German version is authoritative.<\/p>\n<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">5 Min. Read Time<\/p>\n<p><strong>The US authority CISA has listed a vulnerability in N-able N-central as exploited since September 8, 2026, allowing code execution before authentication. N-able observed a handful of successful exploits against N-central customers after the hotfix. The fix is Build 2026.3.1.14. Unpatched servers can be taken over without login.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"color:#69d8ed;text-transform:uppercase;letter-spacing:0.08em;font-size:0.82em;font-weight:700;margin:0 0 16px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.7;\">\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">CISA adds CVE-2026-86218 to its catalog of known exploited vulnerabilities on September 8, 2026.<\/strong> The deadline for US federal agencies expired on September 11, 2026. No German legal obligation follows.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">N-able rates the severity at 10.0 under CVSS 4.0.<\/strong> Any build prior to 2026.3.1.14 allows code execution on the N-central server without authentication.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">On September 6, 2026, N-able stated there was no confirmed exploitation in production.<\/strong> By September 9 at 13:49 UTC, the vendor updated its statement to confirm a handful of successful exploits against N-central customers.<\/li>\n<li style=\"margin-bottom:0;\"><strong style=\"color:#69d8ed;\">Self-hosted N-central users must apply 2026.3 Hotfix 4 (Build 2026.3.1.14) to their servers.<\/strong> For N-central on Demand, the vendor provides a patched version. No agent upgrade is required for this CVE.<\/li>\n<\/ul>\n<\/div>\n<p style=\"border-top:1px solid rgba(230,227,218,0.14);border-bottom:1px solid rgba(230,227,218,0.14);padding:14px 0;margin:28px 0;font-size:0.92em;color:#b8c5ce;\"><strong style=\"color:#69d8ed;\">Related:<\/strong> Attackers Read GitLab Files Without Login &nbsp;\u00b7&nbsp; CISA Sets Deadline: US Agencies Must Patch MikroTik<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">CISA Lists N-central Vulnerability Since September 8<\/h2>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) added <strong>CVE-2026-86218<\/strong> to its catalog of known exploited vulnerabilities on September 8, 2026. This catalog, titled <em>Known Exploited Vulnerabilities<\/em>, documents flaws for which the US agency confirms active exploitation. US federal agencies are legally required to address these vulnerabilities under Binding Operational Directive 26-04. The deadline for this CVE expired on September 11, 2026. For non-US operators, the listing serves as a technical signal with a deadline; no German legal obligation arises.<\/p>\n<div style=\"background:#0a2e3d;color:#fff;padding:24px 28px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0;line-height:1.6;color:#fff;\"><strong>What Is N-able N-central?<\/strong> N-central is a Remote Monitoring and Management (RMM) software solution. IT service providers and internal IT teams use it to centrally manage servers, PCs, and network devices from a single administration server. The now-patched vulnerability resides on this server, not on the endpoint agents.<\/p>\n<\/div>\n<p>N-able, as the CVE Numbering Authority, assigns the flaw a severity score of 10.0 under the Common Vulnerability Scoring System (CVSS) version 4.0. This is the maximum possible rating. This score quantifies the vulnerability\u2019s severity. Security firm Arctic Wolf classifies the flaw as a Static Code Injection (CWE-96), where controllable input is processed as executable code on the server. The National Vulnerability Database has yet to publish its own CVSS 3.1 assessment.<\/p>\n<div style=\"background:#0a2e3d;color:#fff;padding:28px 32px;margin:36px 0;border-radius:8px;\">\n<div style=\"font-size:2.4em;font-weight:800;line-height:1.1;color:#69d8ed;\">10.0 under CVSS 4.0<\/div>\n<div style=\"margin-top:10px;font-size:1.02em;line-height:1.55;color:rgba(255,255,255,0.92);\">N-able assigns the maximum severity score. CISA\u2019s deadline for US federal agencies expired on September 11, 2026.<\/div>\n<div style=\"margin-top:12px;font-size:0.8em;color:rgba(255,255,255,0.6);\">CVE.org on CVSS 4.0 scoring, as of September 6, 2026<\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">The administration server can be hijacked without authentication<\/h2>\n<p>The vendor advisory classifies this vulnerability as a pre-authentication remote code execution flaw. An attacker achieves code execution on the N-central server before providing credentials. The server acts as the central control plane for remote management environments: it initiates services and scripts on managed endpoints, and all access to these devices routes through it. Whoever gains control of the server can access all connected endpoints. According to the vendor\u2019s current statements, there is no separate attack path via the agents on the endpoints for CVE-2026-86218.<\/p>\n<p>All builds prior to 2026.3.1.14 are affected. N-able refers to this build as the first patched version.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">N-able reports a handful of customer incidents<\/h2>\n<p>On September 6, 2026, N-able posted on its status page that there was no confirmed exploitation in production environments. The same notice highlighted unpatched servers as a risk. On September 9, 2026, at 13:49 UTC, N-able updated its corporate blog with new details. At the time of the hotfix release, an independent researcher had successfully exploited the vulnerability in its own production environment; however, no confirmed cases had yet occurred among N-central customers. Since then, the vendor has observed a small number of successful attacks against N-central customers. It does not disclose an exact figure. Investigations are ongoing, and affected customers are being directly supported.<\/p>\n<p>SecurityWeek reported on September 8, 2026, that the flaw was a zero-day, meaning an exploitation method was already known before the patch was released. According to the report, N-able advised checking for newly created user accounts on the server. The same coverage noted scans originating from the IP range 23.234.64.0\/18 as observed activity. The company\u2019s September 9 blog post reiterated these checks, including accounts with a .invalid address. N-central creates internal accounts with this suffix; a new account with this extension could indicate unauthorized creation. Updating to the patched build closes the vulnerability. Whether a single server was abused in the days prior can only be determined through forensic analysis of the specific installation.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Self-hosted systems require Hotfix 4; N-central on Demand is handled by the manufacturer<\/h2>\n<p>N-able has patched the hosted version N-central on Demand itself. No customer action is required there. Customers who self-host N-central must apply 2026.3 Hotfix 4 to their own server. Customers using N-central through a service provider rely on that provider\u2019s server infrastructure. In this model, the end customer of remote support has no direct patching responsibility. The advisory does not require an upgrade for agents on managed devices, as the fix applies solely to the server.<\/p>\n<p>N-able provides 2026.3 Hotfix 4 as Build 2026.3.1.14. This version resolves CVE-2026-86218 on the server. Hotfix 3 (Build 2026.3.1.13) does not cover this CVE. It addressed the related vulnerabilities CVE-2026-86206 and CVE-2026-86207 from the same product line. Users who only applied Hotfix 3 operate a server with the now officially listed vulnerability still open.<\/p>\n<div style=\"background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:22px 20px;margin:32px 0;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"font-size:11px;color:#69d8ed;letter-spacing:0.15em;text-transform:uppercase;margin:0 0 12px;\">Affected Server Versions<\/p>\n<div style=\"overflow-x:auto;-webkit-overflow-scrolling:touch;margin:0 0 32px 0;color:#e6e3da;\">\n<table style=\"width:100%;min-width:560px;border-collapse:collapse;font-size:14px;\">\n<thead>\n<tr>\n<th style=\"text-align:left;padding:6px 8px 8px 0;font-size:11px;letter-spacing:0.8px;text-transform:uppercase;color:#a29e91;font-weight:600;border-bottom:1px solid rgba(105,216,237,0.22);background:#23261f;\">Starting Version<\/th>\n<th style=\"text-align:left;padding:6px 0 8px 0;font-size:11px;letter-spacing:0.8px;text-transform:uppercase;color:#a29e91;font-weight:600;border-bottom:1px solid rgba(105,216,237,0.22);background:#23261f;\">Path to Hotfix 4 (2026.3.1.14)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding:8px 8px 8px 0;border-bottom:1px solid rgba(105,216,237,0.22);color:#e6e3da;\">2025.4, 2026.1, 2026.2, 2026.3<\/td>\n<td style=\"padding:8px 0;border-bottom:1px solid rgba(105,216,237,0.22);color:#69d8ed;font-weight:600;\">Apply Hotfix 4 directly<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:8px 8px 8px 0;border-bottom:1px solid rgba(105,216,237,0.22);color:#e6e3da;\">2026.3.1 Hotfix 1 or 2<\/td>\n<td style=\"padding:8px 0;border-bottom:1px solid rgba(105,216,237,0.22);color:#69d8ed;font-weight:600;\">Apply Hotfix 4 directly<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:8px 8px 8px 0;border-bottom:1px solid rgba(105,216,237,0.22);color:#e6e3da;\">2026.3.1 Hotfix 3 (2026.3.1.13)<\/td>\n<td style=\"padding:8px 0;border-bottom:1px solid rgba(105,216,237,0.22);color:#a29e91;\">Apply Hotfix 4 afterward<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:8px 8px 0 0;color:#e6e3da;\">Older than 2025.4<\/td>\n<td style=\"padding:8px 0 0 0;color:#a29e91;\">First upgrade to 2025.4 or later, then apply Hotfix 4<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"margin:14px 0 0;font-size:0.88em;line-height:1.55;color:rgba(230,227,218,0.75);\">Source: N-able status page for N-central Hotfix 4, as of September 6, 2026.<\/p>\n<\/div>\n<\/div>\n<p>The table applies to self-hosted servers. Users of N-central on Demand do not need to apply a hotfix themselves; the manufacturer provides the updated version.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Each question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Do N-central on Demand customers need to install the hotfix themselves?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">N-able has applied the patch to N-central on Demand automatically. No customer action is required in this hosted version. The patched server version comes from the manufacturer.<\/p>\n<\/details>\n<details>\n<summary><strong>Do the agents on endpoints need to be updated?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">For CVE-2026-86218, N-able provides a server-side hotfix. No mandatory agent upgrade is required. The control layer remains the N-central server.<\/p>\n<\/details>\n<details>\n<summary><strong>Have N-central customers been demonstrably compromised?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">After deploying the hotfix, N-able observed a handful of successful exploits against N-central customers. The manufacturer does not disclose an exact number. CISA lists the vulnerability as exploited.<\/p>\n<\/details>\n<details>\n<summary><strong>Does Hotfix 3 cover the newly listed vulnerability?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Hotfix 3 with build 2026.3.1.13 addresses CVE-2026-86206 and CVE-2026-86207. CVE-2026-86218 is only patched by Hotfix 4 with build 2026.3.1.14.<\/p>\n<\/details>\n<details>\n<summary><strong>Does the CISA deadline of September 11 apply to German operators?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The deadline applies to U.S. federal agencies under Binding Operational Directive BOD 26-04. For operators outside U.S. jurisdiction, the entry serves as a technical advisory.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/cisa-listet-gitlab-dateien-ohne-login-cover-hero-3-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Read Recommendation<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Attackers Access GitLab Files Without Login<\/span><\/span><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/cisa-listet-mikrotik-nach-ssh-uebernahmen-cover-hero-1-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Read Recommendation<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">CISA Sets Deadline: US Agencies Must Patch MikroTik<\/span><\/span><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/cisco-bestaetigt-fmc-root-ohne-anmeldung-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Read Recommendation<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Cisco Confirms Unauthenticated FMC Root Access<\/span><\/span><!--\/ST-LOWER-CARDS--><\/p>\n<p><!--ST-LOWER-CARDS--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2026\/09\/12\/kubernetes-1-37-haelt-gpu-jobs-nativ-zusammen\/\" style=\"display:flex;align-items:center;margin-bottom:10px;padding:12px 14px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Kubernetes only schedules GPU jobs once all pods align<\/span><\/span><\/a><br \/>\n<a href=\"https:\/\/mybusinessfuture.com\/bitkom-logistik-kauft-ki-schult-aber-nur-acht-prozent\/\" style=\"display:flex;align-items:center;margin-bottom:10px;padding:12px 14px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#202528;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Skills shortage: Logistics turns to AI instead of training<\/span><\/span><\/a><br \/>\n<a href=\"https:\/\/www.digital-chiefs.de\/oracle-bindet-ki-kapazitaet-ueber-vorauszahlung\/\" style=\"display:flex;align-items:center;padding:12px 14px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#d65663;margin-bottom:5px;\">digital-chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Oracle has customers pre-finance AI expansion<\/span><\/span><\/a><br \/>\n<!--\/ST-LOWER-CARDS--><\/p>\n<p style=\"text-align:right;color:#868e96;font-size:0.75em;margin-top:40px;\"><em>Image source: AI-generated (September 2026)<\/em><\/p>\n<p class=\"evm-ai-translation-notice-end\" style=\"text-align:right;color:#868e96;font-size:0.75em;margin-top:8px;\"><em>Translated from the German original with AI support. The German version is authoritative.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"CISA lists CVE-2026-86218 as exploited since September 8. Build 2026.3.1.14 fixes the N-central server flaw; self-hosted systems need Hotfix 4.","protected":false},"author":10,"featured_media":23865,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Free N-central access","_yoast_wpseo_title":"N-central: Remote takeover possible without a patch","_yoast_wpseo_metadesc":"CISA lists CVE-2026-86218 as exploited since September 8. The US deadline for federal agencies was September 11. Self-hosted systems need Build 2026.3.1.14.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/n-central-server-bleibt-ohne-anmeldung-uebernehmbar-cover-hero-4.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/09\/n-central-server-bleibt-ohne-anmeldung-uebernehmbar-cover-hero-4.jpg","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[254],"tags":[],"class_list":["post-23943","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung"],"evm_reading_time_minutes":7,"wpml_language":"en","wpml_translation_of":23778,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/23943","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=23943"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/23943\/revisions"}],"predecessor-version":[{"id":23986,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/23943\/revisions\/23986"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/23865"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=23943"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=23943"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=23943"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}