CVE-2026-5269
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.
Published:Jul 14, 2026
Last Modified:Aug 2, 2026
EPS:Jul 14, 2026
EPSS Score:0.00274
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Ciena
Product
Mcp
Ciena
Mcp
Vendor
Ciena
Product
Navigator Ncs
Ciena
Navigator Ncs
Vendor
Ciena
Product
Planner Plus Onprem
Ciena
Planner Plus Onprem
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
