CVE-2026-5267
Last modified
CVE-2026-5267 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information..
Description
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Ciena | Navigator NCS | 7.2 and any older release; 7.2-P01 through 7.2-P07; 8.0; 8.0-P01 through 8.0-P06A; 8.1; 8.1-P01 through 8.1-P06; 8.2; 8.2-P01 through 8.2-P06; 9.0; 9.0-P01 through 9.0-P05A; 9.1; 9.1-P01 through 9.1-P05; 9.2; 9.2-P01 through 9.2-P02; 10.0; 10.0-P01 through 10.0-P01B |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-5267?
How severe is CVE-2026-5267?
How do I fix CVE-2026-5267?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5263URI nameConstraints from constrained intermediate CAs are pa…6.5
- CVE-2026-52630SQL Injection vulnerability in Woltlab WCF v.6.2.4 and befor…9.8
- CVE-2026-5264Heap buffer overflow in DTLS 1.3 ACK message processing. A r…9.8
- CVE-2026-5265When generating an ICMP Destination Unreachable or Packet To…6.5
- CVE-2026-52656An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C a…9.8
- CVE-2026-5266Exposure of Sensitive Information to an Unauthorized Actor v…2.3
- CVE-2026-52673SQL Injection vulnerability in Cboard v.0.4.2 and before all…6.5
- CVE-2026-5268An authentication bypass vulnerability exists in the default…9.1
- CVE-2026-52680Apache Kyuubi REST batch multipart upload handling uses the …9.8
- CVE-2026-52681Sieve CPU resource usage is tracked in the compiled script, …3.1
- CVE-2026-52684If the auth responds very slowly and the records expire in b…3.7
- CVE-2026-52686The issue is a DNSSEC validation bypass where wildcard expan…3.7
Are you affected by CVE-2026-5267?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
