Control Suite (NCS) contains an information exposure vulnerability in an
event-streaming API that does not properly enforce authentication. An
unauthenticated attacker with network access to the affected service could
access the event stream and potentially obtain sensitive information.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Ciena recommends upgrading to the latest available remediated release. For additional details, refer to myciena.com for current software versions, fixes, and security advisories. Remediation and Fixes: Products Remediated Version Navigator NCS 8.0-P06B and later 8.1-P06A and later 8.2-P07 and later 9.0-P05B and later 9.1-P05A and later 9.2-P02A and later 10.0-P01C and later
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ciena.com/product-security |
|
Fri, 25 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information. | |
| Title | Unauthenticated Event Stream Exposure of Session Tokens in Navigator NCS | |
| Weaknesses | CWE-306 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Ciena
Published:
Updated: 2026-09-25T20:40:31.039Z
Reserved: 2026-03-31T19:44:26.584Z
Link: CVE-2026-5267
No data.
Status : Received
Published: 2026-09-25T20:17:11.613
Modified: 2026-09-25T20:17:11.613
Link: CVE-2026-5267
No data.
OpenCVE Enrichment
No data.