CVE-2026-0622

Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

History

03 Feb 2026, 21:38

Type Values Removed Values Added
CWE CWE-798
CPE cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
First Time Open5gs
Open5gs open5gs
References () https://github.com/open5gs/open5gs/issues/2264 - () https://github.com/open5gs/open5gs/issues/2264 - Vendor Advisory, Issue Tracking
References () https://github.com/open5gs/open5gs/issues/856 - () https://github.com/open5gs/open5gs/issues/856 - Issue Tracking
References () https://github.com/open5gs/open5gs/pull/857 - () https://github.com/open5gs/open5gs/pull/857 - Issue Tracking, Patch
References () https://www.kb.cert.org/vuls/id/458022 - () https://www.kb.cert.org/vuls/id/458022 - Third Party Advisory

Information

Published : 2026-01-20 20:16

Updated : 2026-02-03 21:38


NVD link : CVE-2026-0622

Mitre link : CVE-2026-0622

CVE.ORG link : CVE-2026-0622


JSON object : View

Products Affected

open5gs

  • open5gs
CWE
CWE-798

Use of Hard-coded Credentials