๐Ÿ” CVE Alert

CVE-2026-5267

HIGH 7.5

Unauthenticated Event Stream Exposure of Session Tokens in Navigator NCS

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.

CWE CWE-306
Vendor ciena
Product navigator ncs
Published Sep 25, 2026
Last Updated Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for ciena navigator ncs

Be the first to know when new high vulnerabilities affecting ciena navigator ncs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Ciena / Navigator NCS
7.2 and any older release 7.2-P01 through 7.2-P07 8.0 8.0-P01 through 8.0-P06A 8.1 8.1-P01 through 8.1-P06 8.2 8.2-P01 through 8.2-P06 9.0 9.0-P01 through 9.0-P05A 9.1 9.1-P01 through 9.1-P05 9.2 9.2-P01 through 9.2-P02 10.0 10.0-P01 through 10.0-P01B

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
ciena.com: https://www.ciena.com/product-security

Credits

๐Ÿ” Special thanks to Gev Manekshaw