PatchSiren cyber security CVE debrief
CVE-2026-8249 Open5GS CVE debrief
CVE-2026-8249 is a denial of service vulnerability in the SMF component of Open5GS, specifically in the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c. The vulnerability has a CVSS score of 2.1 and is considered low severity. Remote exploitation is possible, and an exploit has been published. Users of Open5GS up to version 2.7.7 should be aware of this denial of service vulnerability and take steps to mitigate it. The vulnerability allows for a denial of service attack, which can be exploited remotely.
- Vendor
- Open5GS
- Product
- Open5GS
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-10
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-10
- Advisory updated
- 2026-07-24
Who should care
Users of Open5GS up to version 2.7.7 should be aware of this denial of service vulnerability and take steps to mitigate it. This includes administrators, security teams, and operators who manage Open5GS installations.
Technical summary
The vulnerability is caused by a flaw in the update_authorized_pcc_rule_and_qos function of the /src/smf/npcf-handler.c file in the SMF component of Open5GS. This flaw allows for a denial of service attack, which can be exploited remotely. The vulnerability has been assigned a CVSS score of 2.1 and is considered low severity. The vulnerability affects Open5GS up to version 2.7.7. Users of Open5GS should review and verify affected scope, severity, and vendor guidance. Administrators and security teams should verify affected Open5GS installations and apply vendor patches or updates when available. The project was informed of the problem early through an issue report but has not responded yet. Evidence from the CVE record and NVD entry supports this assessment, and users should monitor for suspicious activity and implement compensating controls to mitigate potential impact.
Defensive priority
Low priority
Recommended defensive actions
- Inventory and verify affected Open5GS installations
- Apply vendor patches or updates when available
- Monitor for suspicious activity
- Implement compensating controls to mitigate potential impact
- Review and verify affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-05-10T23:16:27.243Z and was last modified on 2026-07-24T07:10:00.200Z. The NVD entry is currently Analyzed. The vulnerability affects Open5GS up to version 2.7.7, specifically the SMF component. The function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c is impacted. The vulnerability has a CVSS score of 2.1 and is considered low severity. Remote exploitation is possible, and an exploit has been published.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8249 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8249
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8249 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8249
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/open5gs/open5gs/
[email protected] - Product
-
Source reference
Unverified legacy reference
URL: https://github.com/open5gs/open5gs/issues/4443
[email protected] - Exploit, Issue Tracking
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/submit/808473
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/vuln/362546
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/362546/cti
[email protected] - Permissions Required, VDB Entry
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.