nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-5269 CVE-2026-5269
CRITICAL
Navigator NCS and MCP System Accounts with Default Passwords
Record summary
CVE-2026-5269 has a selected CVSS score of 9.8 (critical).
Description
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 15, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | <= 8.0 | affected |
Navigator NCSBrowse CIENA / Navigator NCSDefault status: unaffected | CVE List | 8.1 | affected |
Planner Plus OnPremBrowse CIENA / Planner Plus OnPremDefault status: unaffected | CVE List | <= 4.1 | affected |
References
2ciena.com
https://www.ciena.com/product-security