Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset
References
| Link | Resource |
|---|---|
| https://github.com/open5gs/open5gs/issues/2264 | Vendor Advisory Issue Tracking |
| https://github.com/open5gs/open5gs/issues/856 | Issue Tracking |
| https://github.com/open5gs/open5gs/pull/857 | Issue Tracking Patch |
| https://www.kb.cert.org/vuls/id/458022 | Third Party Advisory |
Configurations
History
03 Feb 2026, 21:38
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-798 | |
| CPE | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* | |
| First Time |
Open5gs
Open5gs open5gs |
|
| References | () https://github.com/open5gs/open5gs/issues/2264 - Vendor Advisory, Issue Tracking | |
| References | () https://github.com/open5gs/open5gs/issues/856 - Issue Tracking | |
| References | () https://github.com/open5gs/open5gs/pull/857 - Issue Tracking, Patch | |
| References | () https://www.kb.cert.org/vuls/id/458022 - Third Party Advisory |
Information
Published : 2026-01-20 20:16
Updated : 2026-02-03 21:38
NVD link : CVE-2026-0622
Mitre link : CVE-2026-0622
CVE.ORG link : CVE-2026-0622
JSON object : View
Products Affected
open5gs
- open5gs
CWE
CWE-798
Use of Hard-coded Credentials
