CVE-2026-5268
Last modified
CVE-2026-5268 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| CIENA | 6500 S-Series | R16.96 and prior |
| CIENA | 6500 T-Series | R16.1 and prior |
| CIENA | PTS | R16.1 and prior |
| CIENA | CPL | R12.63 and prior |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-5268?
How severe is CVE-2026-5268?
How do I fix CVE-2026-5268?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5264Heap buffer overflow in DTLS 1.3 ACK message processing. A r…9.8
- CVE-2026-5265When generating an ICMP Destination Unreachable or Packet To…6.5
- CVE-2026-52656An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C a…9.8
- CVE-2026-5266Exposure of Sensitive Information to an Unauthorized Actor v…2.3
- CVE-2026-5267Ciena Navigator Network Control Suite (NCS) contains an info…7.5
- CVE-2026-52673SQL Injection vulnerability in Cboard v.0.4.2 and before all…6.5
- CVE-2026-52680Apache Kyuubi REST batch multipart upload handling uses the …9.8
- CVE-2026-52681Sieve CPU resource usage is tracked in the compiled script, …3.1
- CVE-2026-52684If the auth responds very slowly and the records expire in b…3.7
- CVE-2026-52686The issue is a DNSSEC validation bypass where wildcard expan…3.7
- CVE-2026-52687An attacker that has valid credentials can select a compress…6.5
- CVE-2026-52688RRSIGs with too few labels can lead to bypass of DNSSEC wild…7.5
Are you affected by CVE-2026-5268?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
