Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-5270: Ciena Navigator and Blue Planet Authentication Bypass Risk
CVE-2026-5270
CVE-2026-5270
Summary
Ciena Navigator and Blue Planet products may allow unauthorized access. This is a serious security risk because attackers can bypass security checks and gain access to sensitive areas without a password. Ciena is likely to release a software update to fix this issue, and users should apply the update as soon as it is available.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ciena | navigator ncs | 8.1 |
| ciena | mcp | <= 8.0 |
| ciena | planner plus onprem | <= 4.1 |
| blue planet | inventory | <=24.04.001 |
| blue planet | orchestration | <=24.04.2 |
| blue planet | route optimization & analysis | <=24.04.1.2-R |
| blue planet | unified assurance & analytics | <=24.04 MR1 |
Original title
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by imprope...
Original description
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner that bypasses authentication and associated audit logging controls.
Vulnerability type
CWE-287
Improper Authentication
Published: 14 Jul 2026 · Updated: 16 Jul 2026 · First seen: 14 Jul 2026