A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-10157

CVE-2026-10157: Open5GS Auth Bypass Vulnerability

CVE-2026-10157 is an authentication bypass vulnerability in Open5GS up to version 2.7.6 affecting the NGAP PathSwitchRequest handler. This article covers technical details, affected versions, security impact, and mitigation.

Published: June 4, 2026

CVE-2026-10157 Overview

CVE-2026-10157 is an improper authentication vulnerability in Open5GS through version 2.7.6. The flaw resides in the NGAP PathSwitchRequest message handler implemented in src/amf/ngap-handler.c within the Access and Mobility Management Function (AMF). A remote attacker can manipulate the message to bypass authentication checks, affecting the confidentiality, integrity, and availability of the 5G core network. The maintainers shipped a fix in commit a188e36b1741ffc2252133f59b1bda4f14d3cb5c. Public exploit details have been disclosed through VulDB.

Critical Impact

Remote attackers can exploit the NGAP PathSwitchRequest handler to bypass authentication in the Open5GS AMF, potentially disrupting subscriber sessions and mobility procedures within a 5G core network.

Affected Products

  • Open5GS versions up to and including 2.7.6
  • Open5GS AMF component (NGAP PathSwitchRequest Message Handler)
  • Deployments using the vulnerable src/amf/ngap-handler.c code path

Discovery Timeline

  • 2026-05-31 - CVE-2026-10157 published to NVD
  • 2026-06-01 - Last updated in NVD database

Technical Details for CVE-2026-10157

Vulnerability Analysis

The vulnerability is classified as Improper Authentication [CWE-287]. It affects the NGAP PathSwitchRequest message handler within the Open5GS AMF. NGAP (NG Application Protocol) is the signaling protocol between the 5G Radio Access Network (gNB) and the AMF in the 5G core. The PathSwitchRequest procedure is normally triggered after an Xn-based handover so the target gNB can request the AMF to switch the user plane path. Because the handler does not adequately validate the authentication state associated with the incoming request, an attacker reachable on the N2 interface can submit a crafted PathSwitchRequest message that the AMF processes without enforcing proper identity verification.

Root Cause

The root cause is missing or insufficient authentication validation logic in the PathSwitchRequest processing flow inside src/amf/ngap-handler.c. The handler accepts and acts upon NGAP message parameters before confirming that the request originates from an authenticated, authorized gNB context tied to the targeted UE. The upstream patch a188e36b1741ffc2252133f59b1bda4f14d3cb5c tightens these checks. See GitHub Pull Request #4557 and GitHub Issue #4393 for the maintainer discussion.

Attack Vector

Exploitation requires network reachability to the AMF's N2 (SCTP/NGAP) interface. An attacker with access to that interface can send a forged PathSwitchRequest message and influence AMF state without supplying valid authentication context. The vulnerability does not require user interaction or prior privileges, and the attack complexity is low. Refer to VulDB CVE-2026-10157 for additional exploitation context.

No verified proof-of-concept code is available. The vulnerability is described in prose because no validated exploitation artifact has been published in the referenced advisories.

Detection Methods for CVE-2026-10157

Indicators of Compromise

  • Unexpected NGAP PathSwitchRequest messages from gNBs that have not initiated a corresponding handover procedure.
  • AMF log entries showing PathSwitch processing for UE contexts without matching prior NGAP setup or handover signaling.
  • Anomalous SCTP associations to the AMF N2 interface from previously unseen peer IPs or unauthorized network segments.

Detection Strategies

  • Inspect AMF logs for high-frequency or out-of-sequence PathSwitchRequest events correlated with specific UE identifiers.
  • Deploy NGAP-aware network monitoring on the N2 interface to flag malformed or unauthenticated PathSwitch flows.
  • Correlate NGAP signaling with gNB inventory to identify rogue or spoofed RAN nodes initiating PathSwitch procedures.

Monitoring Recommendations

  • Forward AMF and NGAP signaling logs to a centralized analytics pipeline for anomaly detection across handover events.
  • Baseline normal PathSwitchRequest volume per gNB and alert on deviations exceeding the baseline.
  • Restrict and monitor SCTP connectivity to the AMF, alerting on connections originating outside the authorized RAN segment.

How to Mitigate CVE-2026-10157

Immediate Actions Required

  • Upgrade Open5GS to a release that includes commit a188e36b1741ffc2252133f59b1bda4f14d3cb5c or later.
  • Audit network access to the AMF N2 (SCTP/NGAP) interface and restrict it to authorized gNBs only.
  • Review historical AMF logs for evidence of unexpected PathSwitchRequest processing prior to patching.

Patch Information

The Open5GS project has merged a fix referenced by commit hash a188e36b1741ffc2252133f59b1bda4f14d3cb5c. Operators should pull the fixed source from the GitHub Open5GS Repository or upgrade to a packaged release that incorporates the change. See the GitHub Commit Details for the exact code modifications applied to src/amf/ngap-handler.c.

Workarounds

  • Apply strict network segmentation so only trusted gNBs can reach the AMF N2 interface over SCTP.
  • Enforce IPsec on the N2 interface as specified in 3GPP TS 33.501 to prevent unauthenticated peers from delivering NGAP messages.
  • Disable or block external routing to the AMF management and signaling interfaces until the patch is deployed.
bash
# Configuration example: restrict SCTP/NGAP access to the AMF using nftables
# Replace <AMF_IF>, <NGAP_PORT>, and <TRUSTED_GNB_SUBNET> with environment values
nft add table inet open5gs_amf
nft add chain inet open5gs_amf input { type filter hook input priority 0 \; policy drop \; }
nft add rule inet open5gs_amf input iifname "<AMF_IF>" ip saddr <TRUSTED_GNB_SUBNET> \
    sctp dport <NGAP_PORT> accept
nft add rule inet open5gs_amf input iifname "<AMF_IF>" sctp dport <NGAP_PORT> log prefix "NGAP-DROP: " drop

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechOpen5gs

  • SeverityMEDIUM

  • CVSS Score5.5

  • EPSS Probability0.10%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityLow
  • CWE References
  • CWE-287
  • Technical References
  • GitHub Open5GS Repository

  • GitHub Commit Details

  • GitHub Issue #4393

  • GitHub Pull Request #4557

  • VulDB CVE-2026-10157

  • VulDB Submission #818939

  • VulDB Vulnerability #367410

  • VulDB CTI for 367410
  • Related CVEs
  • CVE-2026-8743: Open5GS Auth Bypass Vulnerability

  • CVE-2026-10115: Open5GS DoS Vulnerability in NF-Profile

  • CVE-2026-10565: Open5GS Race Condition Vulnerability

  • CVE-2026-10114: Open5GS Buffer Overflow Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English