{"id":"CVE-2026-86212","summary":"Open5GS AMF/MME improper authorization","details":"A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch.","modified":"2026-09-08T08:17:41.667207Z","published":"2026-09-06T11:15:10.347Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-266","CWE-285"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86212.json"},"references":[{"type":"WEB","url":"https://github.com/open5gs/open5gs/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86212.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86212"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-86212"},{"type":"ADVISORY","url":"https://vuldb.com/submit/896623"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/399348"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/4680"},{"type":"REPORT","url":"https://vuldb.com/vuln/399348/cti"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open5gs/open5gs","events":[{"introduced":"318eeb49a7dcdff733dec60e02d9c60aefca2fb9"},{"fixed":"9468de94caed2fc940f4a23cbf734651896d0fde"}],"database_specific":{"extracted_events":[{"introduced":"2.7.7"},{"last_affected":"2.7.7"},{"introduced":"2.8.0"},{"last_affected":"2.8.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.7.7","2.8.0","v2.8.0","v2.7.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86212.json","vanir_signatures_modified":"2026-09-08T08:17:41Z","vanir_signatures":[{"digest":{"line_hashes":["276766043567066112765060079984412669896","95091019489435067273910205419919930897","223560679223820286929694267496028354537","114204089614091558078286137775613870649","160839677431703145010095936279536797469","228398062240902524575277013107689908134","118001181266744787861228516581677993932","161565672638429591399677631841483957699","190092453952671040243405099857943330625"],"threshold":0.9},"id":"CVE-2026-86212-1d0c374d","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde","target":{"file":"src/amf/nsmf-handler.c"},"deprecated":false},{"target":{"file":"src/mme/mme-s11-handler.c"},"deprecated":false,"digest":{"line_hashes":["234565523258410933770477311291537274769","187814388082899751817209457919517621337","141760636609019579220927680123886645368","324028080899802441501991527868563829078","308816998575119698673628481698861869146","312755272691013596484350446686799618774","124062907256325291145322870886780821663","137039509220030325241149204247396387748","58985303510487753942844997360333523473"],"threshold":0.9},"id":"CVE-2026-86212-34a8307a","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde"},{"target":{"function":"s1ap_handle_s1_reset","file":"src/mme/s1ap-handler.c"},"deprecated":false,"digest":{"length":3991,"function_hash":"284784654449998525935855539704131849439"},"id":"CVE-2026-86212-5664697a","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde"},{"signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde","target":{"file":"src/mme/s1ap-handler.c"},"deprecated":false,"digest":{"line_hashes":["74458486318500372779413804077503097266","211980494889654004705998485631199001081","132379599945322610550513191953138148249"],"threshold":0.9},"id":"CVE-2026-86212-5cac6dfa","signature_type":"Line"},{"target":{"file":"src/amf/nsmf-handler.c","function":"amf_nsmf_pdusession_handle_update_sm_context"},"deprecated":false,"digest":{"function_hash":"206457382721866979952878067553973841298","length":14942},"id":"CVE-2026-86212-7e7742cc","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde"},{"deprecated":false,"digest":{"function_hash":"210853433854008722496042044020685700032","length":2793},"id":"CVE-2026-86212-961fdbba","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde","target":{"function":"mme_s11_handle_release_access_bearers_response","file":"src/mme/mme-s11-handler.c"}},{"target":{"file":"src/amf/ngap-handler.c"},"deprecated":false,"digest":{"line_hashes":["198225677398156925391756091033033013655","217492913123654214320254027389087285429","165968915594206304899432182565829591267"],"threshold":0.9},"id":"CVE-2026-86212-a1050e38","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde"},{"deprecated":false,"digest":{"function_hash":"32543969046375797849499993343558193315","length":4021},"id":"CVE-2026-86212-dbcacee7","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde","target":{"file":"src/amf/ngap-handler.c","function":"ngap_handle_ng_reset"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}