SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-78157

HIGH · CVSS 7.4 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability in Open5GS 2.8.0 allows for an out-of-bounds read via the pcrf_rx_aar_cb function in the Rx AA-Request Handler, which can be exploited remotely. This could lead to unauthorized access to sensitive information or system instability. Organizations using this version of Open5GS should prioritize applying the provided patch to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78157
Severity
HIGH
CVSS
7.4
EPSS
0.23%

Original NVD Description

A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.