CVE-2026-5267
Unauthenticated Event Stream Exposure of Session Tokens in Navigator NCS
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.
| CWE | CWE-306 |
| Vendor | ciena |
| Product | navigator ncs |
| Published | Sep 25, 2026 |
| Last Updated | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for ciena navigator ncs
Be the first to know when new high vulnerabilities affecting ciena navigator ncs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Ciena / Navigator NCS
7.2 and any older release 7.2-P01 through 7.2-P07 8.0 8.0-P01 through 8.0-P06A 8.1 8.1-P01 through 8.1-P06 8.2 8.2-P01 through 8.2-P06 9.0 9.0-P01 through 9.0-P05A 9.1 9.1-P01 through 9.1-P05 9.2 9.2-P01 through 9.2-P02 10.0 10.0-P01 through 10.0-P01B
Credits
๐ Special thanks to Gev Manekshaw