CVE-2026-0622

Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

History

03 Feb 2026, 21:38

Type Values Removed Values Added
First Time Open5gs open5gs
Open5gs
CWE CWE-798
CPE cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
References () https://github.com/open5gs/open5gs/issues/2264 - () https://github.com/open5gs/open5gs/issues/2264 - Vendor Advisory, Issue Tracking
References () https://github.com/open5gs/open5gs/issues/856 - () https://github.com/open5gs/open5gs/issues/856 - Issue Tracking
References () https://github.com/open5gs/open5gs/pull/857 - () https://github.com/open5gs/open5gs/pull/857 - Issue Tracking, Patch
References () https://www.kb.cert.org/vuls/id/458022 - () https://www.kb.cert.org/vuls/id/458022 - Third Party Advisory

21 Jan 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

20 Jan 2026, 21:16

Type Values Removed Values Added
References
  • () https://www.kb.cert.org/vuls/id/458022 -

20 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-20 20:16

Updated : 2026-02-03 21:38


NVD link : CVE-2026-0622

Mitre link : CVE-2026-0622

CVE.ORG link : CVE-2026-0622


JSON object : View

Products Affected

open5gs

  • open5gs
CWE
CWE-798

Use of Hard-coded Credentials