Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-5269: Ciena Navigator NCS and MCP default passwords leave systems at risk
CVE-2026-5269
CVE-2026-5269
Summary
Ciena's Navigator Network Control Suite and Manage Control Plan have hidden system accounts with easily guessable passwords. These accounts don't have much power on their own, but an attacker could use them to launch a more serious attack. To protect your system, change these default passwords to strong, unique ones.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ciena | navigator ncs | 8.1 |
| ciena | mcp | <= 8.0 |
| ciena | planner plus onprem | <= 4.1 |
Original title
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords...
Original description
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.
Vulnerability type
CWE-1393
Published: 14 Jul 2026 · Updated: 16 Jul 2026 · First seen: 14 Jul 2026