CVE-2026-86212CWE-266CWE-285

Open5GS AMF/MME improper authorization

Medium · published September 6, 2026

CVSS v3.1
4.3
EPSS
In the wild
Unconfirmed
What it is

A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
EPSS
Not scored
Weaknesses
CWE-266 · Incorrect Privilege Assignment; CWE-285 · Improper Authorization
Published
2026-09-06T11:15Z
Timeline
  • 06 SEP 11:15Z
    Open5GS AMF/MME improper authorization
    cvelistv5