Door Access Control Vulnerability in Norwegian Cruise Line Systems
CVE-2026-75907

Currently unrated

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-75907?

The door access control system used by Norwegian Cruise Line has a vulnerability that permits unauthorized entry due to its reliance on a static 7-byte UID stored on an NTAG212 NFC chip. This UID acts as a unique identifier, transmitted openly during access attempts, without any authentication mechanisms to secure it. Consequently, the approach employed lacks a challenge-response feature, making it vulnerable to credential duplication, as it only verifies identity based on this easily accessible UID, rather than ensuring the legitimacy of the holder.

Affected Version(s)

door access control

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.