Description
An authentication bypass vulnerability exists in
the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass
security controls and gain unauthorized access to the underlying filesystem.
Successful exploitation could allow an attacker to read or modify system files.
Published: 2026-07-06
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an authentication bypass flaw (CWE-288) located in the default SFTP server component used across several Ciena products. It permits a remote, unauthenticated attacker to bypass normal login checks and gain direct access to the device’s underlying filesystem. If successfully exploited, the attacker can read or alter system files, potentially leading to full compromise of the device.

Affected Systems

Affected devices include the Ciena 6500 S‑Series, Ciena 6500 T‑Series, Ciena CPL and Ciena PTS products, which share a default SFTP server implementation. No specific product version information is supplied in the CVE, so the vulnerability affects the listed product families regardless of the installed version.

Risk and Exploitability

With a CVSS score of 9.1 the flaw is rated Critical. The EPSS score is less than 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is an external connection to the SFTP service, which listens on a network port without requiring authentication. If an attacker can reach the device from outside, they can immediately bypass authentication, read, and modify system files. The risk is heightened for devices exposed to untrusted networks or those that have the SFTP service enabled.

Generated by OpenCVE AI on July 26, 2026 at 20:27 UTC.

Remediation

Vendor Solution

Ciena recommends upgrading to the latest available remediated release. For additional details, refer to myciena.com for current software versions, fixes, and security advisories.


OpenCVE Recommended Actions

  • Apply vendor patch and upgrade to the latest remediated release as recommended by Ciena.
  • Restrict the SFTP service to known, trusted IP addresses or tunnel it through a VPN to limit exposure.
  • Monitor device logs for unusual authentication attempts or file modifications and promptly.
  • Consider network segmentation to isolate the device from publicly accessible segments.

Generated by OpenCVE AI on July 26, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Ciena
Ciena 6500 S-series
Ciena 6500 T-series
Ciena cpl
Ciena pts
Vendors & Products Ciena
Ciena 6500 S-series
Ciena 6500 T-series
Ciena cpl
Ciena pts

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.
Title SFTP Server Authentication Weakness
Weaknesses CWE-288
References

Subscriptions

Ciena 6500 S-series 6500 T-series Cpl Pts
cve-icon MITRE

Status: PUBLISHED

Assigner: Ciena

Published:

Updated: 2026-07-08T20:18:06.557Z

Reserved: 2026-03-31T19:44:32.296Z

Link: CVE-2026-5268

cve-icon Vulnrichment

Updated: 2026-07-06T18:42:28.543Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:30:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel