← Vulnerability feed

Vulnerability record · CVE-2026-30079 · published 7 April 2026

CVE-2026-30079: Openairinterface oai-cn5g-amf authentication bypass via alternate path vulnerability

OOpenairinterface · Oai Cn5g Amf

In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a SecurityModeComplete message is sent after InitialUERegistration, a registration reject is received followed by a registration accept! This leads the UE to be registered without proper authentication.

9.8 CVSS 3.1 Critical EPSS 0.66% · top 50.5% CWE-288 · Authentication bypass via alternate path
9.8CVSS 3.1 base score
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a SecurityModeComplete message is sent after InitialUERegistration, a registration reject is received followed by a registration accept! This leads the UE to be registered without proper authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/77 ExploitIssue TrackingThird Party Advisory

Track CVE-2026-30079 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-30075Openairinterface oai-cn5g-amf classic buffer overflow vulnerabilityOpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a N…EPSS 0.66%7.5CVE-2026-30080Openairinterface oai-cn5g-amf authentication bypass by capture-replay vulnerabilityOpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if …EPSS 0.35%7.5CVE-2026-30078Openairinterface oai-cn5g-amf improper input validation vulnerabilityOpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message sp…EPSS 0.49%7.5CVE-2025-66786Openairinterface oai-cn5g-amf improper input validation vulnerabilityOpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send malicious JSO…EPSS 0.36%7.5CVE-2025-65805Openairinterface oai-cn5g-amf stack-based buffer overflow vulnerabilityOpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote attackers can launch a denial-o…EPSS 0.37%10.0CVE-2026-20079Cisco Secure Firewall Management Center authentication bypass to rootCisco Secure Firewall Management Center (FMC) Software contains an authentication bypass caused by an improper system process created at boot time. A…KEVEPSS 88%analysed9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed8.2CVE-2026-18556N-able N-central authentication bypass via alternate pathN-able N-central contains an authentication bypass (CWE-288) that lets an attacker reach protected functionality through an alternate path or channel…KEVEPSS 7.9%analysed

Source: NIST National Vulnerability Database (record CVE-2026-30079), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.