Sceawere

Vulnerability Detail

CVE-2026-78158UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Open5GS AMF Improper Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
2h ago
Vendor
n/a
Product
Open5GS
Attack Type
Improper Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in Open5GS 2.8.0. This vulnerability affects unknown code of the component AMF UEContextReleaseRequest Path Handler. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-24T01:16:56.990Z",
  "pubdate": "2026-08-24T01:16:56.990Z",
  "executiveSummary": "A vulnerability classified as problematic has been identified in Open5GS version 2.8.0. This security flaw resides within the AMF UEContextReleaseRequest Path Handler component and involves improper authorization controls.\nThe vulnerability allows remote attackers to execute manipulations that bypass intended access restrictions, leading to improper authorization states within the core network architecture.\nThe affected product is Open5GS version 2.8.0, specifically impacting the Access and Mobility Management Function (AMF) processing pathways associated with user equipment context release requests.\nThe risk implications include potential unauthorized state transitions and manipulation of signaling pathways within the 5G core network, which could affect session integrity and service availability.\nAttacker capabilities require the ability to interact with the vulnerable component remotely over the network, exploiting the lack of robust authorization checks within the path handler.\nExploitation requirements involve sending crafted signaling messages or requests targeting the AMF UEContextReleaseRequest Path Handler without proper validation of the originator's authorization context.",
  "technicalDetails": "The root cause of this vulnerability stems from insufficient or absent authorization validation checks within the AMF UEContextReleaseRequest Path Handler of Open5GS version 2.8.0. When the component processes incoming requests related to the release of user equipment contexts, it fails to adequately verify whether the entity initiating the request possesses the necessary privileges or valid authorization state.\nThe vulnerable component is identified as the AMF UEContextReleaseRequest Path Handler within the Open5GS Access and Mobility Management Function. This handler is responsible for parsing, evaluating, and executing context release procedures for connected user equipment.\nNetwork exposure is remote, as the affected handlers process incoming signaling traffic. An attacker positioned with network access to the exposed interfaces can interact with the AMF and transmit manipulated requests.\nThe attack flow proceeds as follows: First, the remote attacker crafts a specialized signaling payload targeting the AMF UEContextReleaseRequest Path Handler. Second, the attacker transmits this payload across the network interface to the Open5GS deployment. Third, the AMF receives the request and routes it to the vulnerable path handler. Fourth, due to the absence of stringent access controls and authorization enforcement, the component processes the request as legitimate. Finally, the improper authorization permits the execution of the requested context release or state manipulation, bypassing security boundaries.\nAuthentication and privilege requirements for exploitation depend on network topology and interface exposure, but the flaw highlights a breakdown in authorization enforcement where valid session context or caller privileges are not rigorously authenticated or validated prior to state execution.\nPost-exploitation impact includes unauthorized disruption of user sessions, forced disconnection of user equipment, and potential destabilization of core network management functions relying on accurate and secure UE context states."
}
CVE-2026-78158: Open5GS AMF Improper Authorization Vulnerability (MEDIUM Severity, CVSS: 6.3) - Sceawere