Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset
References
| Link | Resource |
|---|---|
| https://github.com/open5gs/open5gs/issues/2264 | Vendor Advisory Issue Tracking |
| https://github.com/open5gs/open5gs/issues/856 | Issue Tracking |
| https://github.com/open5gs/open5gs/pull/857 | Issue Tracking Patch |
| https://www.kb.cert.org/vuls/id/458022 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-01-20 20:16
Updated : 2026-02-03 21:38
NVD link : CVE-2026-0622
Mitre link : CVE-2026-0622
CVE.ORG link : CVE-2026-0622
JSON object : View
Products Affected
open5gs
- open5gs
CWE
CWE-798
Use of Hard-coded Credentials
