CVE-2026-75907: Security vulnerability

Published Sep 24, 2026
·
Updated

The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no challenge-response capability that would resist copying.

Event History

Sep 24, 2026
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
Description

Frequently Asked Questions

1

What does an attacker need to gain unauthorized entry?

An attacker needs the static 7-byte UID from a valid NTAG212-based credential. The UID is transmitted in cleartext on every read and can be copied because the credential does not use challenge-response authentication.

2

Who is realistically exposed?

Access-controlled areas protected by the affected Norwegian Cruise Line asset's NTAG212 credentials are exposed if the reader grants entry based solely on the credential UID. Anyone able to obtain a valid credential's UID could potentially present a copied credential.

3

What can be done if the access-control system cannot be changed immediately?

The provided information does not identify a compensating technical control. Since UID-only validation cannot distinguish an original credential from a copy, physical and operational controls would be needed until authentication that resists copying is deployed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203