CVE-2026-8743

MEDIUM

Open5GS AMF/MME context.c ran_ue_find_by_amf_ue_ngap_id improper authorization

Title source: cna
STIX 2.1

Description

A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 5746b8576cfceec18ed87eb7d8cf11b1fb4cd8b1. It is suggested to install a patch to address this issue.

References (7)

Core 7
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-364330 | Open5GS AMF/MME context.c ran_ue_find_by_amf_ue_ngap_id improper authorization
https://vuldb.com/vuln/364330
Signature, Permissions Required signature permissions-required
VDB-364330 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/364330/cti
Third Party Advisory third-party-advisory
Submit #814559 | Open5GS 2.7.6 Incorrect Authorization
https://vuldb.com/submit/814559
Exploit exploit issue-tracking
https://github.com/open5gs/open5gs/issues/4498

Scores

CVSS v3 6.3
EPSS 0.0022
EPSS Percentile 12.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (8)
None/Open5GS 2.7.0
None/Open5GS 2.7.1
None/Open5GS 2.7.2
None/Open5GS 2.7.3
None/Open5GS 2.7.4
None/Open5GS 2.7.5
None/Open5GS 2.7.6
open5gs/open5gs < 2.7.6
Published May 17, 2026
Tracked Since May 17, 2026