CVE-2026-5267
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ciena | Navigator NCS | 7.2 and any older release | affected |
| Ciena | Navigator NCS | 7.2-P01 through 7.2-P07 | affected |
| Ciena | Navigator NCS | 8.0 | affected |
| Ciena | Navigator NCS | 8.0-P01 through 8.0-P06A | affected |
| Ciena | Navigator NCS | 8.1 | affected |
| Ciena | Navigator NCS | 8.1-P01 through 8.1-P06 | affected |
| Ciena | Navigator NCS | 8.2 | affected |
| Ciena | Navigator NCS | 8.2-P01 through 8.2-P06 | affected |
| Ciena | Navigator NCS | 9.0 | affected |
| Ciena | Navigator NCS | 9.0-P01 through 9.0-P05A | affected |
| Ciena | Navigator NCS | 9.1 | affected |
| Ciena | Navigator NCS | 9.1-P01 through 9.1-P05 | affected |
| Ciena | Navigator NCS | 9.2 | affected |
| Ciena | Navigator NCS | 9.2-P01 through 9.2-P02 | affected |
| Ciena | Navigator NCS | 10.0 | affected |
| Ciena | Navigator NCS | 10.0-P01 through 10.0-P01B | affected |
Weaknesses
- CWE-306: CWE-306 Missing authentication for critical function
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.