CVE-2026-30079: Critical severity openairinterface OpenAirInterface AMF vulnerability
In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a SecurityModeComplete message is sent after InitialUERegistration, a registration reject is received followed by a registration accept! This leads the UE to be registered without proper authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30079?
CVE-2026-30079 is considered a critical vulnerability due to its potential to allow authentication bypass during UE registration.
How do I fix CVE-2026-30079?
To fix CVE-2026-30079, users should upgrade OpenAirInterface AMF to a version beyond 2.2.0 that addresses this vulnerability.
What are the potential impacts of CVE-2026-30079?
The potential impacts of CVE-2026-30079 include unauthorized access to the network since authentication can be bypassed.
Which versions of software are affected by CVE-2026-30079?
CVE-2026-30079 affects OpenAirInterface AMF version 2.2.0.
How does CVE-2026-30079 exploit the system?
CVE-2026-30079 exploits the system by allowing out-of-sequence messages to cause incorrect state transitions, resulting in authentication bypass.