CVE-2026-92416Medium· 4.3▾ TwilightPoC availableA vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Report Request Handler. The manipulation le…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 23.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
Exploit / PoC code exists
0.4%
A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Report Request Handler. The manipulation leads to reachable assertion. The attack may be initiated remotely. The identifier of the patch is e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9. It is suggested to install a patch to address this issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91855Medium· 5.3A security flaw has been discovered in Open5GS up to 2.7.7
CVE-2026-86212Medium· 4.3A vulnerability has been found in Open5GS 2.7.7/2.8.0
CVE-2026-92417Medium· 6.5A vulnerability was found in Open5GS up to 2.8.0
CVE-2026-90707High· 8.3A security flaw has been discovered in Open5GS up to 2.7.x
CVE-2026-8252Medium· 4.3A vulnerability was determined in Open5GS up to 2.7.7
CVE-2026-8251Medium· 4.3A vulnerability was found in Open5GS up to 2.7.7