cienaCVE-2026-5267
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication.
High7.5CVE-2026-5267 · Published Sep 25, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Navigator NCS Vendor | <= 7.2 and any older release | No fix yet |
| <= 7.2-P01 through 7.2-P07 | No fix yet | |
| <= 8.0 | No fix yet | |
| <= 8.0-P01 through 8.0-P06A | No fix yet |
Details and references
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- no source yet
- Weakness
- CWE-306
More ciena advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. CVE-2026-5269Critical9.8no fix yet | Critical9.8 | No fix yet |
| Jul 14 | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. CVE-2026-5270Critical9.8no fix yet | Critical9.8 | No fix yet |
| Jul 6 | An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. CVE-2026-5268Critical9.1no fix yet | Critical9.1 | No fix yet |