PatchSiren cyber security CVE debrief
CVE-2026-75907 Norwegian Cruise Line CVE debrief
A Norwegian Cruise Line asset's door access control system uses NTAG212 NFC chips with static 7-byte UIDs for authentication, which is insecure because UIDs are sent in the clear and not secret. This allows for easy copying of credentials, as the system only performs identification, not authentication, and lacks challenge-response capabilities. The CVE-2026-75907 vulnerability in Norwegian Cruise Line's door access control system allows for easy copying of credentials, potentially leading to unauthorized access. Defenders should prioritize verifying the affected asset inventory, assessing exposure, and implementing compensating controls.
- Vendor
- Norwegian Cruise Line
- Product
- door access control
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-24
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-24
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for Norwegian Cruise Line assets, specifically those managing door access control systems, should assess exposure and implement compensating controls to prevent unauthorized access.
Why it matters
The CVE-2026-75907 vulnerability in Norwegian Cruise Line's door access control system allows for easy copying of credentials, potentially leading to unauthorized access. Defenders should prioritize verifying the affected asset inventory, assessing exposure, and implementing compensating controls.
- Defenders need to verify the affected asset inventory and assess exposure to prevent unauthorized access.
- The lack of challenge-response capability in the credential makes it vulnerable to copying.
- Defenders should implement compensating controls to prevent unauthorized access until a fix is available.
Technical summary
The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no challenge-response capability that would resist copying. The NTAG212 NFC chip's static 7-byte UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. This allows for easy copying of credentials, as the system only performs identification, not authentication, and lacks challenge-response capabilities.
Defensive priority
Defenders should prioritize verifying the affected asset inventory, assessing exposure, and implementing compensating controls to prevent unauthorized access.
Recommended defensive actions
- Verify the affected asset inventory and assess exposure
- Implement compensating controls to prevent unauthorized access
- Monitor for potential copying of credentials
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE description and NVD detail page provide information on the vulnerability, but further verification is needed to determine the affected asset inventory and potential exposure. The NTAG212 NFC chip's static 7-byte UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no challenge-response capability that would resist copying. The official N
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75907 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75907
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75907 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75907
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://kb.cert.org/vuls/id/676317
-
Source reference
Unverified legacy reference
URL: https://www.kb.cert.org/vuls/id/676317
af854a3a-2127-422b-91ae-364da2661108
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.