CVE-2026-5270
Awaiting Analysis Awaiting Analysis - Queue

Authentication Bypass in Ciena Network Control Suite

Vulnerability report for CVE-2026-5270, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-15

Assigner: Ciena

Description

An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner that bypasses authentication and associated audit logging controls.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ciena navigator_network_control_suite *
ciena manage_control_plan *
ciena blue_planet *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass flaw in Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. It occurs due to improper handling of HTTP request paths and headers, allowing unauthenticated attackers to manipulate requests and bypass authentication and audit logging controls.

Detection Guidance

This vulnerability cannot be detected with specific commands based on the provided CVE details. It involves improper handling of HTTP request paths and headers in Ciena products, which may require manual inspection of network traffic or application logs for unusual authentication bypass attempts.

Impact Analysis

An attacker could exploit this to gain unauthorized access to sensitive systems, bypass security controls, and perform actions without being logged. This may lead to data breaches, unauthorized configuration changes, or disruption of network services.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations by enabling unauthorized access to personal or health data, failing to maintain proper audit trails, and violating data protection requirements for access controls and logging.

Mitigation Strategies

Apply vendor-provided patches or updates for Ciena Navigator Network Control Suite, Manage Control Plan, and Blue Planet products. Disable unnecessary HTTP services and restrict network access to these systems. Monitor logs for unauthorized access attempts and review authentication bypass indicators.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5270. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart