Junglewise Threat Intelligence

CVE-2026-78158: Open5GS AMF UEContextReleaseRequest improper authorization in RAN ownership

CVE-2026-78158 · Severity: medium · CVSS 6.3 · Published 2026-08-24

Technologies: Open5GS. Vendors: Open5GS.

Executive brief

Open5GS is a 5G core network implementation that manages connections between mobile devices and cellular infrastructure. A flaw in its Access and Mobility Management Function (AMF) allows an attacker on a different base station to fraudulently release another base station's mobile device contexts, potentially causing service disruption for legitimate users without authorization.

Technical details

The vulnerability is an improper authorization / missing ownership validation flaw in the AMF's UEContextReleaseRequest message handler. The AMF fails to verify that a UEContextReleaseRequest originates from the NG-RAN node (base station) that actually owns/controls the target UE context; instead, it accepts the request from any associated gNB. An attacker controlling a second gNB association can send a UEContextReleaseRequest with another gNB's UE NGAP identifiers, causing the AMF to release that UE's context on the original gNB association. The vulnerability is network-reachable (requires NG-RAN/NGAP protocol access) and no authentication is bypassed—the flaw is in application-level context ownership authorization logic. A patch or update has not yet been released as of the advisory date.

Affected products

  • Open5GS Open5GS 2.8.0

Timeline

  • 2026-06-26: disclosed
  • 2026-08-24: advisory

References

Related threats