PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8249 Open5GS CVE debrief

CVE-2026-8249 is a denial of service vulnerability in the SMF component of Open5GS, specifically in the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c. The vulnerability has a CVSS score of 2.1 and is considered low severity. Remote exploitation is possible, and an exploit has been published. Users of Open5GS up to version 2.7.7 should be aware of this denial of service vulnerability and take steps to mitigate it. The vulnerability allows for a denial of service attack, which can be exploited remotely.

Vendor
Open5GS
Product
Open5GS
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-10
Original CVE updated
2026-07-24
Advisory published
2026-05-10
Advisory updated
2026-07-24

Who should care

Users of Open5GS up to version 2.7.7 should be aware of this denial of service vulnerability and take steps to mitigate it. This includes administrators, security teams, and operators who manage Open5GS installations.

Technical summary

The vulnerability is caused by a flaw in the update_authorized_pcc_rule_and_qos function of the /src/smf/npcf-handler.c file in the SMF component of Open5GS. This flaw allows for a denial of service attack, which can be exploited remotely. The vulnerability has been assigned a CVSS score of 2.1 and is considered low severity. The vulnerability affects Open5GS up to version 2.7.7. Users of Open5GS should review and verify affected scope, severity, and vendor guidance. Administrators and security teams should verify affected Open5GS installations and apply vendor patches or updates when available. The project was informed of the problem early through an issue report but has not responded yet. Evidence from the CVE record and NVD entry supports this assessment, and users should monitor for suspicious activity and implement compensating controls to mitigate potential impact.

Defensive priority

Low priority

Recommended defensive actions

  • Inventory and verify affected Open5GS installations
  • Apply vendor patches or updates when available
  • Monitor for suspicious activity
  • Implement compensating controls to mitigate potential impact
  • Review and verify affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-05-10T23:16:27.243Z and was last modified on 2026-07-24T07:10:00.200Z. The NVD entry is currently Analyzed. The vulnerability affects Open5GS up to version 2.7.7, specifically the SMF component. The function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c is impacted. The vulnerability has a CVSS score of 2.1 and is considered low severity. Remote exploitation is possible, and an exploit has been published.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-10T23:16:27.243Z and has not been modified since then. The NVD entry is currently Analyzed.