CVE-2026-2522

MEDIUM

Open5GS <=2.7.6 - Memory Corruption

Title source: llm
STIX 2.1

Description

A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is an unknown function of the file /src/mme/esm-build.c of the component MME. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.346110
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.346110
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.738336
Issue Tracking issue-tracking
https://github.com/open5gs/open5gs/issues/4283
Various Sources product
https://github.com/open5gs/open5gs/

Scores

CVSS v3 5.3
EPSS 0.0012
EPSS Percentile 30.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119
Status published
Products (1)
open5gs/open5gs < 2.7.6
Published Feb 16, 2026
Tracked Since Feb 18, 2026