Junglewise Threat Intelligence

CVE-2026-5270: Ciena Navigator NCS and Blue Planet authentication bypass

CVE-2026-5270 · Severity: info · Published 2026-07-14

Executive brief

Ciena Navigator NCS, MCP, and Blue Planet products are used by telecommunications providers to manage and automate large-scale network infrastructure. A security vulnerability in these systems allows an unauthorized person to bypass login requirements by sending specially crafted web requests. If exploited, an attacker could gain access to sensitive network management functions and hide their activities by bypassing audit logs, potentially leading to unauthorized network configuration changes or service disruptions.

Technical details

An authentication bypass vulnerability (CWE-287) exists in multiple Ciena and Blue Planet network management products due to improper handling of HTTP request paths and headers. An unauthenticated remote attacker can exploit this flaw by crafting specific HTTP requests that circumvent the authentication logic and associated audit logging mechanisms. This allows the attacker to perform actions within the management suites without valid credentials. Affected products include Navigator NCS 8.1, MCP versions 8.0 and prior, and various versions of Blue Planet Inventory, Orchestration, and Analytics platforms.

Affected products

  • Ciena Navigator NCS 8.1
  • Ciena MCP <= 8.0
  • Ciena Planner Plus OnPrem <= 4.1
  • Blue Planet Inventory <=24.04.001, <=23.12.401, <=23.08.302, <=23.04.701
  • Blue Planet Orchestration <=24.04.2, <=23.12.3, <=23.08.4, <=23.04.2
  • Blue Planet Route Optimization & Analysis <=24.04.1.2-R, <=23.12.1.6-R, <=23.08.1.6-R, <=23.04.P01-9-R
  • Blue Planet Unified Assurance & Analytics <=24.04 MR1, <=23.12 MR3, <=23.04. MR4

Timeline

  • 2026-07-14: disclosed: Initial advisory publication

References

Related threats