Description
A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch.
Published: 2026-09-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper authorization in Open5GS AMF/MME enabling unauthorized network access
Action: Apply Patch
AI Analysis

Impact

A bug in the AMF/MME component of Open5GS 2.7.7 and 2.8.0 allows an attacker to manipulate the code and obtain improper authorization. The flaw can be exploited remotely and has been publicly disclosed, meaning an attacker can potentially gain unauthorized access to core network functions used for mobile subscriber management.

Affected Systems

The vulnerability affects Open5GS deployments running version 2.7.7 or 2.8.0. It specifically targets the AMF/MME component responsible for authentication and mobility management.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS is unavailable, and the vulnerability is not cataloged in CISA’s KEV list. Attackers can launch the exploit from a remote position, requiring only network access to the Open5GS instance. Once authorized, the attacker could bypass normal authorization checks and potentially execute further network-level attacks.

Generated by OpenCVE AI on September 6, 2026 at 13:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Open5GS to the patched version that includes commit 9468de94caed2fc940f4a23cbf734651896d0fde
  • Apply strong network segmentation and firewall rules to limit external access to the AMF/MME services, ensuring only trusted entities communicate with the Open5GS core
  • Enable detailed logging for AMF/MME authentication flows and regularly review logs to detect anomalous activity

Generated by OpenCVE AI on September 6, 2026 at 13:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 06 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch.
Title Open5GS AMF/MME improper authorization
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:36:38.668Z

Reserved: 2026-09-05T18:53:45.570Z

Link: CVE-2026-86212

cve-icon Vulnrichment

Updated: 2026-09-11T20:04:58.936Z

cve-icon NVD

Status : Deferred

Published: 2026-09-06T12:17:15.423

Modified: 2026-09-11T21:17:37.160

Link: CVE-2026-86212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T13:15:06Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization