Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-5270: Ciena Navigator and Blue Planet Authentication Bypass Risk

CVE-2026-5270 CVE-2026-5270
Summary

Ciena Navigator and Blue Planet products may allow unauthorized access. This is a serious security risk because attackers can bypass security checks and gain access to sensitive areas without a password. Ciena is likely to release a software update to fix this issue, and users should apply the update as soon as it is available.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ciena navigator ncs 8.1
ciena mcp <= 8.0
ciena planner plus onprem <= 4.1
blue planet inventory <=24.04.001
blue planet orchestration <=24.04.2
blue planet route optimization & analysis <=24.04.1.2-R
blue planet unified assurance & analytics <=24.04 MR1
Original title
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by imprope...
Original description
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner that bypasses authentication and associated audit logging controls.
Vulnerability type
CWE-287 Improper Authentication
Published: 14 Jul 2026 · Updated: 16 Jul 2026 · First seen: 14 Jul 2026