Description
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.
Published: 2026-07-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Hidden internal system accounts are used by Ciena’s Navigator Network Control Suite, Manage Control Plan, and Planner Plus OnPrem and contain default compromised account with other weaknesses to perform a larger attack, potentially escalating privileges on the affected systems.

Affected Systems

The vulnerability affects Ciena products: Navigator NCS (versions earlier than 8.2 or 8.1-P02), Manage Control Plan (MCP) versions earlier than 8.0-P04 or 7.2-P07, and Planner Plus OnPrem versions earlier than 4.2 or 4.1-P01. These systems were identified by the CNA as vulnerable to the default password issue.

Risk and Exploitability

The flaw carries a CVSS score of 9.8 and an EPSS <1%, indicating a low current exploitation probability but a high potential impact. It is not listed in CISA’s KEV catalog. likely attack vector requires initial network access or a locally compromised host to exploit the default accounts; after gaining access, the attacker could leverage additional weaknesses to raise privileges. The combination of limited account permissions and the threat is significant if the default passwords remain unchanged.

Generated by OpenCVE AI on July 31, 2026 at 04:20 UTC.

Remediation

Vendor Solution

Ciena recommends upgrading to the latest available remediated release. For additional details, refer to myciena.com for current software versions, fixes, and security advisories.   Remediation and Fixes:  Products Remediated Version Navigator NCS >= 8.2, 8.1-P02 MCP 8.0-P04, 7.2-P07 Planner Plus OnPrem >= 4.2, 4.1-P01


OpenCVE Recommended Actions

  • Upgrade Navigator NCS to the remedi or newer, or 8.1-P02 or newer, as released by Ciena.
  • Upgrade Manage Control Plan (MCP) to at least version 8.0-P04, or 7.2-P07, following Ciena’s recommendations.
  • Upgrade Planner Plus OnPrem to 4.2 or newer, or 4.1-P01 or newer, to eliminate the default password issue.

Generated by OpenCVE AI on July 31, 2026 at 04:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Ciena
Ciena mcp
Ciena navigator Ncs
Ciena planner Plus Onprem
Vendors & Products Ciena
Ciena mcp
Ciena navigator Ncs
Ciena planner Plus Onprem

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.
Title Navigator NCS and MCP System Accounts with Default Passwords
Weaknesses CWE-1393
References

Subscriptions

Ciena Mcp Navigator Ncs Planner Plus Onprem
cve-icon MITRE

Status: PUBLISHED

Assigner: Ciena

Published:

Updated: 2026-07-15T14:30:50.769Z

Reserved: 2026-03-31T19:44:35.713Z

Link: CVE-2026-5269

cve-icon Vulnrichment

Updated: 2026-07-15T14:30:41.570Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:29Z

Weaknesses