PatchSiren cyber security CVE debrief
CVE-2026-8268 Open5gs CVE debrief
CVE-2026-8268 is a denial of service vulnerability in the OpenAPI_list_create function of the SMF component in Open5GS up to 2.7.7. The vulnerability can be exploited remotely. Users of Open5GS should be aware of this issue and take necessary precautions until a patch is available. This includes reviewing system configurations, monitoring for potential exploitation attempts, and planning for an upgrade to a version beyond 2.7.7 when available. The project was informed early through an issue report but has not yet responded with a patch.
- Vendor
- Open5gs
- Product
- Open5GS
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-11
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-11
- Advisory updated
- 2026-07-23
Who should care
Users of Open5GS up to version 2.7.7 should be aware of this denial of service vulnerability and take necessary precautions. This includes reviewing system configurations, monitoring for potential exploitation attempts, and planning for an upgrade to a version beyond 2.7.7 when available. Operators, platform administrators, vulnerability management teams, and security teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Technical summary
A vulnerability has been found in Open5GS up to 2.7.7 in the OpenAPI_list_create function of the SMF component. This issue leads to denial of service and can be exploited remotely. The project was informed early through an issue report but has not yet responded with a patch. Users should review system configurations, monitor for potential exploitation attempts, and plan for an upgrade to a version beyond 2.7.7 when available.
Defensive priority
Low priority due to CVSS score of 2.1 and lack of immediate response from the vendor. However, users should still take necessary precautions to protect their systems and review compensating controls for exposed systems while remediation is scheduled and verified.
Recommended defensive actions
- Inventory and verify affected Open5GS installations
- Apply compensating controls to limit exposure
- Monitor for potential exploitation attempts
- Consider upgrading to a version beyond 2.7.7 when available
- Review system configurations for potential vulnerabilities
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence is based on CVE and NVD records. Detailed information about the vulnerability is limited. Further investigation and verification are recommended. The project was informed early through an issue report but has not responded yet. Open5GS up to 2.7.7 is affected by this vulnerability. Defenders should verify affected scope, severity, and vendor guidance.
Official resources
-
CVE-2026-8268 CVE record
CVE.org
-
CVE-2026-8268 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Product
-
Source reference
[email protected] - Exploit, Issue Tracking
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
[email protected] - Permissions Required, VDB Entry
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-11T04:16:20.403Z and has not been modified since then.