CVE-2026-5269
Last modified
CVE-2026-5269 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| CIENA | Navigator NCS | 8.1 |
| CIENA | MCP | <= 8.0 |
| CIENA | Planner Plus OnPrem | <= 4.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-5269?
How severe is CVE-2026-5269?
How do I fix CVE-2026-5269?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-52673SQL Injection vulnerability in Cboard v.0.4.2 and before all…6.5
- CVE-2026-5268An authentication bypass vulnerability exists in the default…9.1
- CVE-2026-52680Apache Kyuubi REST batch multipart upload handling uses the …9.8
- CVE-2026-52684If the auth responds very slowly and the records expire in b…3.7
- CVE-2026-52686The issue is a DNSSEC validation bypass where wildcard expan…3.7
- CVE-2026-52688RRSIGs with too few labels can lead to bypass of DNSSEC wild…7.5
- CVE-2026-52690Spoofing replies to Recursor might mark an IP of an authorit…5.9
- CVE-2026-52692Unauthenticated Sensitive Data Exposure in Affiliates Manage…7.5
- CVE-2026-52693Unauthenticated SQL Injection in eCommerce Product Catalog <…9.3
- CVE-2026-52694Unauthenticated Sensitive Data Exposure in Signature Add-On …7.5
- CVE-2026-52695Unauthenticated Sensitive Data Exposure in ABC Crypto Checko…7.5
- CVE-2026-52696Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 …7.5
Are you affected by CVE-2026-5269?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
