logo

CVE-2026-0622: Hardcoded Secret Exposes Open5GS 5G Core Networks

ID: a30d1b1a-940e-5500-a66e-e04f1ce9c416

STIX ID: report--a30d1b1a-940e-5500-a66e-e04f1ce9c416

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-0622) was discovered in the Open5GS WebUI: the application shipped with hardcoded default JWT signing secrets set to a known value ('change-me'), allowing anyone to forge valid admin tokens and gain full administrative access to the WebUI, exposing subscriber data and system configuration. A patch was released in v2.7.6 (July 2025) that removes the hardcoded defaults and introduces a self-contained .env for secrets; administrators should immediately set strong, random values for process.env.SECRET_KEY and process.env.JWT_SECRET_KEY if they cannot patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.