← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 24, 2026 · 15:44via CERT/CC Vulnerability Notes

VU#676317: Norwegian Cruise Line door access controller contains an improper authentication vulnerability

Brief

Overview

Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identification (RFID) device to grant unauthorized entry to areas secured by these controllers.

Description

Norwegian Cruise Line is a global cruise company that operates a modern fleet sailing to destinations worldwide. As described in CVE-2026-75907 , the affected card reader authenticates NFC credentials only by checking their static 7-byte UID. A UID is not a secret and does not support cryptographic challenge‑response operations, so it cannot serve as a reliable authentication factor.

Although the keycard's NTAG212 tag contains a memory block with a printed serial number and a value resembling a signature, the reader does not inspect this data during the access-control process.

Read more on CERT/CC Vulnerability Notes→