CVE-2026-78158: Open5GS AMF UEContextReleaseRequest Path improper authorization
A flaw has been found in Open5GS 2.8.0. This vulnerability affects unknown code of the component AMF UEContextReleaseRequest Path Handler. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low privileges and can exploit the issue remotely. No user interaction is required, and exploitation has low attack complexity.
What security impact could successful exploitation have?
Successful exploitation can result in improper authorization and has low impacts on confidentiality, integrity, and availability according to the provided CVSS metrics.
Which deployment should be prioritized for review?
Review Open5GS deployments using version 2.8.0, particularly systems exposing the AMF UEContextReleaseRequest handling path to remotely reachable low-privileged actors.