---
id: CVE-2026-93309
title: A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10
summary: >-
  A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by
  this issue is some unknown functionality of the component VES Collector.
  Executing a manipulation can lead to allocation of resources. The attack may
  be launched …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-400
  - CWE-770
vendor: O-RAN-SC
product: SMO OAM
affected:
  - smo_oam 2025-06-10
published: '2026-09-18'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T03:16:57.930'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93309'
references:
  - url: 'https://gist.github.com/fklement/639eb04a12cc5c015f9b960b0de96d80'
    label: cna@vuldb.com
  - url: 'https://lf-o-ran-sc.atlassian.net/browse/SMO-203'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-93309'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/942312'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/406595'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/406595/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00521
epssPercentile: 0.4168
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T02:00:39.106673Z'
ingestedAt: '2026-09-17T23:31:20.689Z'
---

## Overview

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
