An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner that bypasses authentication and associated audit logging controls.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ciena.com/product-security |
|
History
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Blue Planet
Blue Planet inventory Blue Planet orchestration Blue Planet route Optimization & Analysis Blue Planet unified Assurance & Analytics Ciena Ciena mcp Ciena navigator Ncs Ciena planner Plus Onprem |
|
| Vendors & Products |
Blue Planet
Blue Planet inventory Blue Planet orchestration Blue Planet route Optimization & Analysis Blue Planet unified Assurance & Analytics Ciena Ciena mcp Ciena navigator Ncs Ciena planner Plus Onprem |
Wed, 15 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 14 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner that bypasses authentication and associated audit logging controls. | |
| Title | Authentication Bypass in Navigator and Blue Planet Products | |
| Weaknesses | CWE-287 | |
| References |
|
Status: PUBLISHED
Assigner: Ciena
Published: 2026-07-14T22:24:34.750Z
Updated: 2026-07-15T12:39:32.248Z
Reserved: 2026-03-31T19:44:41.118Z
Link: CVE-2026-5270
Updated: 2026-07-15T12:39:11.872Z
No data.
No data.