CVE-2026-0622

MEDIUM

Open5gs < 2.7.6 - Hard-coded Credentials

Title source: rule

Description

Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset

Exploits (1)

nomisec SUSPICIOUS
by cyberdudebivash · poc
https://github.com/cyberdudebivash/CYBERDUDEBIVASH-5G-Core-Key-Rotation-Ghost-Admin-Auditor

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 11.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-798
Status published

Affected Products (1)

open5gs/open5gs < 2.7.6

Timeline

Published Jan 20, 2026
Tracked Since Feb 18, 2026