PT-2026-30848 · Git+1 · Oai-Cn5G-Amf
CVE-2026-30079
·
Published
2026-04-07
·
Updated
2026-04-07
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenAirInterface version V2.2.0
Description
In the AMF component, out-of-sequence messages cause an incorrect state transition during the UE registration procedure. This allows authentication to be bypassed completely. Specifically, if a SecurityModeComplete message is sent after InitialUERegistration, the system issues a registration reject followed by a registration accept, resulting in the UE being registered without proper authentication.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oai-Cn5G-Amf