{"id":"CVE-2026-5267","title":"Ciena Navigator Network\nControl Suite (NCS) contains an information exposure vulnerability in an\nevent-streaming API that does not properly enforce authentication","summary":"Ciena Navigator Network\nControl Suite (NCS) contains an information exposure vulnerability in an\nevent-streaming API that does not properly enforce authentication. An\nunauthenticated attacker with network access to the affected service c…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-306"],"vendor":"Ciena","product":"Navigator NCS","affected":["navigator_ncs 7.2 and any older release","navigator_ncs 7.2-P01 through 7.2-P07","navigator_ncs 8.0","navigator_ncs 8.0-P01 through 8.0-P06A","navigator_ncs 8.1","navigator_ncs 8.1-P01 through 8.1-P06","navigator_ncs 8.2","navigator_ncs 8.2-P01 through 8.2-P06","navigator_ncs 9.0","navigator_ncs 9.0-P01 through 9.0-P05A","navigator_ncs 9.1","navigator_ncs 9.1-P01 through 9.1-P05","navigator_ncs 9.2","navigator_ncs 9.2-P01 through 9.2-P02","navigator_ncs 10.0","navigator_ncs 10.0-P01 through 10.0-P01B"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T21:17:23.633","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5267","references":[{"url":"https://www.ciena.com/product-security","label":"7bd90cf1-1651-495e-9ae8-9415fb3c9feb"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-25T20:40:10.302755Z"},"ingestedAt":"2026-09-25T20:17:49.419Z","slug":"CVE-2026-5267","body":"## Overview\n\nCiena Navigator Network\nControl Suite (NCS) contains an information exposure vulnerability in an\nevent-streaming API that does not properly enforce authentication. An\nunauthenticated attacker with network access to the affected service could\naccess the event stream and potentially obtain sensitive information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":211183,"id":"CVE-2026-5267","ts":1790371216136,"field":"cvss","old":null,"new":"7.5"},{"seq":211182,"id":"CVE-2026-5267","ts":1790371216136,"field":"severity","old":"none","new":"high"}]}