---
id: CVE-2026-86212
title: A vulnerability has been found in Open5GS 2.7.7/2.8.0
summary: >-
  A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability
  affects unknown code of the component AMF/MME. The manipulation leads to
  improper authorization. The attack is possible to be carried out remotely. The
  exploit has…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-266
  - CWE-285
product: Open5GS
affected:
  - Open5GS 2.7.7
  - Open5GS 2.8.0
published: '2026-09-06'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T21:17:37.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86212'
references:
  - url: 'https://github.com/open5gs/open5gs/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde
    label: cna@vuldb.com
  - url: 'https://github.com/open5gs/open5gs/issues/4680'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86212'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/896623'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399348'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399348/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-11T20:04:57.823872Z'
epss: 0.00488
epssPercentile: 0.39399
ingestedAt: '2026-09-07T03:04:07.487Z'
---

## Overview

A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
