CVE-2026-15720: Pre-auth heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler
Published Jul 14, 2026
·Updated
In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.
Affected Software
1 affected component
open5gs open5gs<=2.7.7
Event History
Jul 14, 2026
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15720?
The severity of CVE-2026-15720 is high with a score of 8.6.
2
How do I fix CVE-2026-15720?
To fix CVE-2026-15720, update Open5GS to version 2.7.8 or later, as this version addresses the vulnerability.
3
What impact does CVE-2026-15720 have on systems?
CVE-2026-15720 may result in subscriber-wide denial of service due to a pre-authentication heap out-of-bounds read.
4
Which software is affected by CVE-2026-15720?
CVE-2026-15720 affects Open5GS versions up to and including 2.7.7.
5
Is CVE-2026-15720 exploitable remotely?
Yes, CVE-2026-15720 can be exploited remotely due to its nature of being a pre-authentication vulnerability.