A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The identifier of the patch is a188e36b1741ffc2252133f59b1bda4f14d3cb5c. It is suggested to install a patch to address this issue.
Metrics
Affected Vendors & Products
References
History
Sun, 31 May 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The identifier of the patch is a188e36b1741ffc2252133f59b1bda4f14d3cb5c. It is suggested to install a patch to address this issue. | |
| Title | Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication | |
| First Time appeared |
Open5gs
Open5gs open5gs |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Open5gs
Open5gs open5gs |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-31T00:30:10.718Z
Reserved: 2026-05-30T06:05:02.777Z
Link: CVE-2026-10157
No data.
Status : Received
Published: 2026-05-31T02:16:32.613
Modified: 2026-05-31T02:16:32.613
Link: CVE-2026-10157
No data.
OpenCVE Enrichment
Updated: 2026-05-31T02:30:37Z