CVE-2026-52023: Kamailio Kamailio vulnerability
Published Sep 1, 2026
·Updated
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the imsregistrarpcscf module, specifically the pcscfsavepending/savepending path and security-agreement parsing in secagree.c:parsesecagree()
Affected Software
1 affected component
kamailio Kamailio<6.1.1
Event History
Sep 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are exposed to this denial-of-service issue?
Kamailio deployments using the ims_registrar_pcscf module are implicated. The affected code path is pcscf_save_pending/save_pending and its security-agreement parsing.
2
What does an attacker need to do to trigger the issue?
The issue can be triggered remotely through security-agreement parsing in sec_agree.c:parse_sec_agree(). No authentication requirement or other prerequisite is stated in the available data.
3
Which versions are affected?
Kamailio version 6.1.1 and earlier are identified as affected.