OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-5267

HIGH · CVSS 7.5 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Ciena Navigator Network Control Suite is vulnerable due to an information exposure flaw in its event-streaming API, which fails to enforce proper authentication. This allows unauthenticated attackers with network access to potentially retrieve sensitive information from the event stream. Organizations using this suite should prioritize remediation to mitigate the risk of data breaches.

CVE
CVE-2026-5267
Severity
HIGH
CVSS
7.5
EPSS
0.36%

Original NVD Description

Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.