CienaCVE-2026-5269
Ciena MCP: privilege escalation
Critical9.8CVE-2026-5269 · Published Jul 14, 2026 · updated Jul 15, 2026
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| MCP Product | <= <= 8.0 | No fix yet |
| Navigator NCS Product | <= 8.1 | No fix yet |
| Planner Plus OnPrem Product | <= <= 4.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-1393
More Ciena advisories
All Ciena| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 25 | Ciena Navigator NCS: information disclosure | High7.5 | No fix yet |
| Jul 14 | Ciena Inventory: authentication bypass | Critical9.8 | No fix yet |
| Jul 6 | Ciena 6500 S-Series: authentication bypass | Critical9.1 | No fix yet |