Description
A flaw has been found in Open5GS 2.8.0. This vulnerability affects unknown code of the component AMF UEContextReleaseRequest Path Handler. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely.
Published: 2026-08-24
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Open5GS 2.8.0, within the AMF UEContextReleaseRequest Path Handler, can lead to improper authorization when a request is manipulated. This issue aligns with CWE‑266 and CWE‑285, indicating weaknesses in authorization logic that allow an attacker to bypass legitimate controls. By exploiting this flaw, an attacker could potentially gain unauthorized access to control‑plane operations for a user equipment, enabling further malicious actions.

Affected Systems

The affected product is the Open5GS open‑source 5G core network, specifically version 2.8.0. No other versions or vendor variations are listed in the available data. The flaw lies in the AMF component’s UEContextReleaseRequest Path Handler.

Risk and Exploitability

The CVSS base score of 5.3 designates a moderate level of risk, while no EPSS score is available, so the exploitation probability cannot be quantified. It is not listed in the CISA KEV catalog, indicating no known active exploitation. The attack vector is remote; the description states that manipulation can be executed over the network, and the vulnerability originates from improper authorization checks, implying that an attacker could forge or alter a UEContextReleaseRequest to obtain unauthorized privileges. No higher‑level impact such as denial of service or code execution is reported in the advisory.

Generated by OpenCVE AI on August 24, 2026 at 01:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Open5GS release that contains a fix for improper authorization or install the vendor patch for CVE-2026-78158.
  • Restrict external access to the AMF UEContextReleaseRequest endpoint using firewall rules or network segmentation until a patch is applied.
  • Monitor Open5GS security advisories and apply future updates promptly to eliminate this authorization flaw.

Generated by OpenCVE AI on August 24, 2026 at 01:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Open5GS 2.8.0. This vulnerability affects unknown code of the component AMF UEContextReleaseRequest Path Handler. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely.
Title Open5GS AMF UEContextReleaseRequest Path improper authorization
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-24T00:15:08.598Z

Reserved: 2026-08-23T11:34:40.843Z

Link: CVE-2026-78158

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T01:16:56.990

Modified: 2026-08-24T01:16:56.990

Link: CVE-2026-78158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T01:30:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization