Skip to content
CienaCVE-2026-5268

Ciena 6500 S-Series: authentication bypass

Critical9.1CVE-2026-5268 · Published Jul 6, 2026 · updated Jul 8, 2026

An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.

Ciena advisory

Affected versions

PackageAffectedFixed in
6500 S-Series
Product
<= R16.96 and priorNo fix yet
6500 T-Series
Product
<= R16.1 and priorNo fix yet
CPL
Product
<= R12.63 and priorNo fix yet
PTS
Product
<= R16.1 and priorNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-288

More Ciena advisories

All Ciena
Advisory
Ciena Navigator NCS: information disclosure
High7.5Sep 25
Ciena Inventory: authentication bypass
Critical9.8Jul 14
Ciena MCP: privilege escalation
Critical9.8Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.