PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8730 Open5gs CVE debrief

CVE-2026-8730 is a low-severity denial-of-service issue in Open5GS’s NRF component. According to the published record, manipulating the nfInstanceId argument in ogs_sbi_nf_instance_set_id can disrupt service remotely, and an exploit has already been published. The issue is reported to affect Open5GS up to version 2.7.6.

Vendor
Open5gs
Product
Unknown
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-17
Original CVE updated
2026-05-19
Advisory published
2026-05-17
Advisory updated
2026-05-19

Who should care

Operators and integrators running Open5GS NRF services, especially deployments exposed to untrusted or remote clients, should review this issue. It is also relevant to teams that rely on Open5GS for mobile core infrastructure availability.

Technical summary

The flaw is described in /lib/sbi/context.c within the NRF component, specifically in ogs_sbi_nf_instance_set_id. A crafted or manipulated nfInstanceId value can lead to denial of service over the network. The source record maps the issue to CWE-404 and lists the impact primarily as availability loss.

Defensive priority

Low to medium. The CVSS score is low, but remote reachability and a published exploit raise operational urgency for exposed NRF deployments.

Recommended defensive actions

  • Confirm whether your Open5GS deployment includes the NRF component and whether it is reachable from untrusted networks.
  • Inventory versions and treat Open5GS up to 2.7.6 as potentially affected based on the published record.
  • Monitor vendor and project channels for an official fix or advisory update.
  • Review access controls and network exposure around NRF endpoints to reduce remote attack surface.
  • If you cannot patch immediately, increase monitoring for availability disruptions affecting NRF services.

Evidence notes

This debrief is based on the supplied NVD record and its cited references, including the Open5GS repository and issue link. The source description states that the flaw affects Open5GS up to 2.7.6, that it is reachable remotely, and that an exploit has been published. The vendor attribution in the source data is weak/uncertain, so the product framing is kept limited to the referenced Open5GS project.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8730 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8730

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8730 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8730

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.