Sceawere
Vulnerability Detail
CVE-2026-86212UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Open5GS Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 2h ago
- Vendor
- n/a
- Product
- Open5GS
- Attack Type
- Improper Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-06T12:17:15.423Z",
"pubdate": "2026-09-06T12:17:15.423Z",
"executiveSummary": "A critical security vulnerability involving improper authorization has been identified in Open5GS versions 2.7.7 and 2.8.0. The flaw resides within the AMF (Access and Mobility Management Function) and MME (Mobility Management Entity) components, which are central to core network signaling and subscriber management.\nThis vulnerability allows remote, unauthenticated, or unauthorized actors to bypass established access control policies. By exploiting this flaw, an attacker can perform unauthorized operations within the 5G or 4G core network, potentially leading to unauthorized service access, disruption of network operations, or manipulation of subscriber data.\nThe risk is categorized as high due to the exposure of the signaling plane and the availability of public exploit disclosures. The exploitation does not require physical access to the infrastructure, as the attack is conducted remotely. Organizations utilizing these versions of Open5GS must prioritize the application of the official security patch to prevent unauthorized access and potential service degradation.\nThe vulnerability highlights a failure in the logic responsible for verifying user or device credentials and authorization states during critical signaling procedures.",
"technicalDetails": "The vulnerability is characterized as an improper authorization flaw within the Open5GS AMF/MME architecture. The root cause pertains to a logic error in the handling of signaling messages, specifically where the state machine or the authorization logic fails to strictly validate the session context or the requester's privileges before processing sensitive protocol operations.\nIn the context of the 5G AMF and 4G MME, these components act as the entry points for User Equipment (UE) signaling. The vulnerability occurs when the system fails to correctly verify the authorization state during the transition of mobility management or session management states. An attacker can craft malicious signaling messages that exploit these authorization gaps to initiate procedures that should otherwise be restricted or require successful authentication/authorization.\nThe attack flow generally involves the following steps: 1) The attacker reaches the AMF/MME via the N1/N2 or S1-MME interface. 2) The attacker sends a specifically crafted protocol data unit (PDU) or signaling message that mimics a valid subscriber request. 3) The target component, lacking robust authorization checks at the specific functional code path, processes the request as if it originated from a verified or authorized source. 4) The manipulation results in the system executing commands or state changes that the attacker is not legitimately authorized to perform.\nThe exploitation method leverages the fact that the AMF/MME must process high volumes of signaling traffic; if the authorization logic is bypassed, the component becomes susceptible to command injection or illegitimate state transitions. Since the vulnerability is remotely exploitable, it poses a direct threat to the availability and integrity of the core network. The potential post-exploitation impact includes the ability to perform unauthorized mobility management procedures, potential redirection of traffic, or the denial of service (DoS) to legitimate subscribers by exhausting signaling resources or corrupting session states.\nAffected versions are limited to Open5GS 2.7.7 and 2.8.0. The vulnerability demonstrates a failure in secure coding practices where input validation and authorization checks were insufficient for the exposed signaling interfaces. The remediation involves applying the provided patch identifier 9468de94caed2fc940f4a23cbf734651896d0fde, which implements the necessary access control logic and integrity checks to prevent unauthorized state manipulation within the identified component."
}