A vulnerability has been identified in Open5GS version 2.8.0 affecting the function pcrf_rx_aar_cb within the file src/pcrf/pcrf-rx-path.c, part of the Rx AA-Request Handler component. The flaw allows an attacker to trigger an out-of-bounds read through manipulation of the affected function. The attack can be initiated remotely without requiring physical access to the target system. Open5GS is an open-source implementation of 5G and LTE core network components, making this vulnerability relevant to telecommunications infrastructure. A patch has been identified with commit hash c18dc6938bf63cc7374315d3dca303d92066e746 on the official GitHub repository. Users are strongly recommended to apply the patch immediately to mitigate potential exploitation. The vulnerability is tracked under CVE-2026-78157 and is also referenced in VulDB under entry 394540.