PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75907 Norwegian Cruise Line CVE debrief

A Norwegian Cruise Line asset's door access control system uses NTAG212 NFC chips with static 7-byte UIDs for authentication, which is insecure because UIDs are sent in the clear and not secret. This allows for easy copying of credentials, as the system only performs identification, not authentication, and lacks challenge-response capabilities. The CVE-2026-75907 vulnerability in Norwegian Cruise Line's door access control system allows for easy copying of credentials, potentially leading to unauthorized access. Defenders should prioritize verifying the affected asset inventory, assessing exposure, and implementing compensating controls.

Vendor
Norwegian Cruise Line
Product
door access control
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-28
Advisory published
2026-09-24
Advisory updated
2026-09-28

Who should care

Defenders responsible for Norwegian Cruise Line assets, specifically those managing door access control systems, should assess exposure and implement compensating controls to prevent unauthorized access.

Why it matters

The CVE-2026-75907 vulnerability in Norwegian Cruise Line's door access control system allows for easy copying of credentials, potentially leading to unauthorized access. Defenders should prioritize verifying the affected asset inventory, assessing exposure, and implementing compensating controls.

  • Defenders need to verify the affected asset inventory and assess exposure to prevent unauthorized access.
  • The lack of challenge-response capability in the credential makes it vulnerable to copying.
  • Defenders should implement compensating controls to prevent unauthorized access until a fix is available.

Technical summary

The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no challenge-response capability that would resist copying. The NTAG212 NFC chip's static 7-byte UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. This allows for easy copying of credentials, as the system only performs identification, not authentication, and lacks challenge-response capabilities.

Defensive priority

Defenders should prioritize verifying the affected asset inventory, assessing exposure, and implementing compensating controls to prevent unauthorized access.

Recommended defensive actions

  • Verify the affected asset inventory and assess exposure
  • Implement compensating controls to prevent unauthorized access
  • Monitor for potential copying of credentials
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE description and NVD detail page provide information on the vulnerability, but further verification is needed to determine the affected asset inventory and potential exposure. The NTAG212 NFC chip's static 7-byte UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no challenge-response capability that would resist copying. The official N

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75907 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75907

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75907 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75907

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.