Vulnerability Description
In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a SecurityModeComplete message is sent after InitialUERegistration, a registration reject is received followed by a registration accept! This leads the UE to be registered without proper authentication.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openairinterface | Oai-Cn5G-Amf | 2.2.0 |
Related Weaknesses (CWE)
References
- https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/77ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2026-30079?
CVE-2026-30079 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a SecurityModeComp...
How severe is CVE-2026-30079?
CVE-2026-30079 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-30079?
Check the references section above for vendor advisories and patch information. Affected products include: Openairinterface Oai-Cn5G-Amf.