CVE-2026-30046: High severity open5gs open5gs vulnerability
Published Aug 27, 2026
·Updated
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
Affected Software
1 affected component
open5gs open5gs=2.7.6
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What systems are exposed to this denial-of-service issue?
Open5GS v2.7.6 deployments with a reachable NUDM-UECM interface are exposed. The issue is triggered through that interface rather than requiring access to an unrelated component.
2
What must an attacker do to exploit the issue?
An attacker must be able to send a crafted DELETE request to the reachable NUDM-UECM interface. The provided data does not state that authentication or other prerequisites are required.