SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-5269

CRITICAL · CVSS 9.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Ciena's Navigator Network Control Suite and Manage Control Plan contain hidden internal accounts with predictable default passwords, posing a critical security risk. Although these accounts have limited permissions, they can be exploited in conjunction with other vulnerabilities to escalate privileges and compromise the system. Organizations using these products should prioritize immediate remediation to mitigate potential attacks.

CVE
CVE-2026-5269
Severity
CRITICAL
CVSS
9.8
EPSS
0.27%

Original NVD Description

In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.