← Vulnerability feed

Vulnerability record · CVE-2026-30080 · published 8 April 2026

CVE-2026-30080: Openairinterface oai-cn5g-amf authentication bypass by capture-replay vulnerability

OOpenairinterface · Oai Cn5g Amf

OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registration request with only security capability IA0, OpenAirInterface accepts and proceeds. This downgrade security context can lead to the possibility of replay attack.

7.5 CVSS 3.1 High EPSS 0.35% · top 74.4% CWE-294 · Authentication bypass by capture-replay
7.5CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
25 Jul 2026Last modified by NVD

Description

OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registration request with only security capability IA0, OpenAirInterface accepts and proceeds. This downgrade security context can lead to the possibility of replay attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/78 ExploitIssue TrackingThird Party Advisory
https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/78 ExploitIssue TrackingThird Party Advisory

Track CVE-2026-30080 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-30079Openairinterface oai-cn5g-amf authentication bypass via alternate path vulnerabilityIn OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authenticati…EPSS 0.66%7.5CVE-2026-30075Openairinterface oai-cn5g-amf classic buffer overflow vulnerabilityOpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a N…EPSS 0.66%7.5CVE-2026-30078Openairinterface oai-cn5g-amf improper input validation vulnerabilityOpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message sp…EPSS 0.49%7.5CVE-2025-66786Openairinterface oai-cn5g-amf improper input validation vulnerabilityOpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send malicious JSO…EPSS 0.36%7.5CVE-2025-65805Openairinterface oai-cn5g-amf stack-based buffer overflow vulnerabilityOpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote attackers can launch a denial-o…EPSS 0.37%9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2026-30080), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.