Junglewise Threat Intelligence

CVE-2026-5268: Ciena multiple products authentication bypass in SFTP server

CVE-2026-5268 · Severity: info · Published 2026-07-06

Executive brief

A security flaw has been identified in the file transfer component of several Ciena networking products, including the 6500 S-Series and T-Series platforms. This vulnerability allows an unauthorized person to bypass login requirements and access the device's internal file system over the network. If exploited, an attacker could steal sensitive configuration data or modify critical system files, potentially leading to a full compromise of the networking equipment.

Technical details

An authentication bypass vulnerability (CWE-288) exists in the default SFTP server component utilized across multiple Ciena networking platforms. The flaw allows a remote, unauthenticated attacker to bypass standard security controls and gain direct access to the underlying filesystem. By exploiting this alternate path or channel, an attacker can read or modify sensitive system files without providing valid credentials. Affected products include the 6500 S-Series (R16.96 and prior), 6500 T-Series (R16.1 and prior), PTS (R16.1 and prior), and CPL (R12.63 and prior).

Affected products

  • Ciena 6500 S-Series R16.96 and prior
  • Ciena 6500 T-Series R16.1 and prior
  • Ciena PTS R16.1 and prior
  • Ciena CPL R12.63 and prior

Timeline

  • 2026-07-06: disclosed
  • 2026-07-06: advisory

References