CVE-2026-5268

An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.
References
Configurations

No configuration.

History

06 Jul 2026, 19:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

06 Jul 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-06 16:16

Updated : 2026-07-08 21:16


NVD link : CVE-2026-5268

Mitre link : CVE-2026-5268

CVE.ORG link : CVE-2026-5268


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel