Description

Norwegian Cruise Line’s access-control system has been affected by a vulnerability tracked as CVE-2026-75907, which can allow unauthorized access through replay of an NFC keycard identifier. The issue is related to the way certain door readers validate NTAG212 NFC cards. Instead of relying on a cryptographic authentication mechanism, the system can use the card’s static UID as the credential, creating an opportunity for an attacker to reproduce an authorized identifier. An attacker who obtains brief access to a legitimate keycard can capture its NFC identifier with compatible hardware and subsequently emulate or reproduce that identifier. Because the reader does not sufficiently distinguish between the original card and a duplicated credential, the replayed identifier may be accepted as valid. This represents a capture-and-replay authentication weakness and could allow an unauthorized person to enter areas protected by the affected access-control infrastructure. Organizations operating similar NFC-based access systems should avoid treating static card identifiers as authentication secrets. Access-control deployments should use cryptographically protected credentials, challenge-response authentication, and additional controls for sensitive locations. Administrators should also review access logs for unusual credential activity and apply vendor-supported updates or replacement readers where available. Adding another authentication factor for restricted areas can further reduce the consequences of a compromised or duplicated NFC credential.