Security Advisories
At Ciena, the security of our products and services is a top priority. To facilitate responsible reporting of security vulnerabilities in our products and services, we have established this Notice of Vulnerability Disclosure Policy (VDP).
We are committed to providing secure and reliable solutions that meet the highest standards of quality and performance. We also care about the potential impact of security vulnerabilities on our customers and their end-users. With this goal in mind, our dedicated Product Security Incident Response Team (PSIRT) is responsible for responding to cyber incidents and vulnerability reports affecting Ciena’s products and services.
For more information about the following vulnerabilities, please visit the Ciena Support Portal.
Date: July 6, 2026
Title: SFTP Server Authentication Weakness
Description
An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed below. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.
Product name(s):
6500 S-Series: R16.96 and prior
6500 T-Series: R16.1 and prior
PTS: R16.1 and prior
CPL: R12.63 and prior
Solution / Remediation:
Ciena has released updates and provided a mitigation to address this vulnerability. Customers are advised to upgrade as soon as possible. Please refer to myciena.com for the latest releases.
Date: July 14, 2026
Description
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet (BP) products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner that bypasses authentication and associated audit logging controls.
| Products | Affected Version |
|---|---|
| BP Inventory | <=24.04.001, <=23.12.401, <=23.08.302, <=23.04.701 |
| BP Orchestration | <=24.04.2, <=23.12.3, <=23.08.4, <=23.04.2 |
| BP Route Optimization & Analysis | <=24.04.1.2-R, <=23.12.1.6-R, <=23.08.1.6-R, <=23.04.P01-9-R |
| BP Unified Assurance & Analytics | <=24.04 MR1, <=23.12 MR3, <=23.04 MR4 |
| Navigator NCS | 8.1 |
| MCP | <=8.0 |
| Planner Plus OnPrem | <=4.1 |
Solution / Remediation:
Ciena recommends upgrading to the latest available remediated release. For additional details, refer to myciena.com for current software versions, fixes, and security advisories.
Date: July 14, 2026
Description: In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an attack using one of these accounts with other potential weaknesses to launch a more significant attack, possibly leading to escalation of privilege on the system.
| Products | Affected Version |
|---|---|
| Navigator NCS | 8.1 |
| MCP | <= 8.0 |
| Planner Plus OnPrem | <= 4.1 |
Solution / Remediation:
Ciena recommends upgrading to the latest available remediated release. For additional details, refer to myciena.com for current software versions, fixes, and security advisories.
Date: March 4, 2024
Title: SAML implementation allows privilege escalation CVE-2024-2005
Description
In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected.
Product name(s): Blue Planet Inventory (BPI); Blue Planet Orchestration (BPO); Blue Planet Route Optimization and Analysis (ROA); Blue Planet Unified Assurance and Analytics (UAA).
Blue Planet has released software updates that address this vulnerability for the affected products. Customers are advised to upgrade their Blue Planet products to the latest software version as soon as possible. The software updates can be downloaded from the Ciena Support Portal.
The issue is fixed in:
- BPI: 21.10 MR11, 22.02 MR5, 22.08 MR4
- BPO: 22.02.03, 22.08.05, 22.12.02
- ROA: 22.02.P01.11-R, 22.08.P01.1-R, 22.12.P01.2.1-R
- UAA: 22.02 MR5, 22.12 MR2



