CVE-2026-5269 Details
Description
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.
A vulnerability exists in Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP) due to hidden system accounts used for internal operations. Some of these accounts have default passwords that could be easily guessed. Although these accounts have limited permissions individually, an attacker might exploit them in conjunction with other vulnerabilities to launch a more significant attack, potentially leading to unauthorized privilege escalation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ciena.com/product-security | Ciena |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1393 | Use of Default Password | Ciena |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | Ciena |