CVE-2026-82590
Received Received - Intake

Reachable Assertion in Open5GS SMF Component

Vulnerability report for CVE-2026-82590, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: VulDB

Description

A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of the file src/smf/nudm-handler.c of the component SMF. Executing a manipulation of the argument preemptCap can lead to reachable assertion. The attack may be launched remotely. Upgrading to version 2.8.0 is sufficient to fix this issue. This patch is called 4554405f29bffd7562abedbee63484825bd90cd5. You should upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open5gs open5gs to 2.7.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a reachable assertion issue in Open5GS versions up to 2.7.7. It exists in the function smf_nudm_sdm_handle_get within the SMF component. An attacker can remotely manipulate the preemptCap argument to trigger an assertion failure, potentially causing the system to crash or behave unexpectedly.

Detection Guidance

This vulnerability is specific to Open5GS versions up to 2.7.7. To detect it, check the installed version of Open5GS using the command 'open5gs-version' or inspect the source code for the file 'src/smf/nudm-handler.c' and the function 'smf_nudm_sdm_handle_get'.

Impact Analysis

The impact includes potential denial of service due to system crashes, disruption of network services relying on Open5GS, and unauthorized manipulation of network functions. Remote attackers could exploit this to destabilize the affected system.

Compliance Impact

The vulnerability in Open5GS (CVE-2026-82590) involves a reachable assertion due to manipulation of the preemptCap argument, which could lead to denial-of-service conditions. This may impact compliance with standards like GDPR or HIPAA by disrupting the availability of critical network services, potentially affecting data processing or access controls.

Mitigation Strategies

Upgrade Open5GS to version 2.8.0 or later immediately. The patch is identified as commit 4554405f29bffd7562abedbee63484825bd90cd5. No other mitigation steps are mentioned as necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82590. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart