CVE-2026-30079Disclosure(openairinterface / oai-cn5g-amf)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a SecurityModeComplete message is sent after InitialUERegistration, a registration reject is received followed by a registration accept! This leads the UE to be registered without proper authentication.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oai-cn5g-amf

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
oai-cn5g-amf

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-20: 2Technical Details · 2026-04-20: 204-20
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30079 In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed… https://www.cve.org/CVERecord?id=CVE-2026-30079 ----- Traducción: CVE-2026-30079 En … http://infoflow.cloud`

    Post summary

    The tweet announces a newly disclosed CVE (CVE-2026-30079) affecting OpenAirInterface AMF, detailing that out-of‑sequence messages can lead to authentication bypass, and links to the official CVE record without providing PoC, exploit code, or patch information.

    0000092
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-30079 In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed… https://www.cve.org/CVERecord?id=CVE-2026-30079

    Post summary

    The post offers a brief technical description of CVE‑2026‑30079 in OpenAirInterface’s AMF, noting an authentication bypass flaw, but it provides no proof of exploitation, PoC, or mitigation.

    00000268
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenairinterfaceoai-cn5g-amf2.2.0--

Explore more