PT-2026-32974 · Free5Gc · Free5Gc

CVE-2026-40247

·

Published

2026-04-14

·

Updated

2026-07-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions free5GC versions 4.2.1 and earlier
Description An improper path validation issue exists in the UDR service. The endpoint 'GET /nudr-dr/v2/application-data/influenceData/{influenceId}/{subscriptionId}' is designed to operate only when the influenceId path segment is exactly 'subs-to-notify'. However, the function HandleApplicationDataInfluenceDataSubsToNotifySubscriptionIdGet fails to stop execution after sending an HTTP 404 response when validation fails. This allows an unauthenticated attacker with access to the 5G Service Based Interface to read arbitrary Traffic Influence Subscriptions, including SUPIs/IMSIs, DNNs, S-NSSAIs, and callback URIs, by providing any value for the influenceId variable.
Recommendations Update free5GC to a version where the HandleApplicationDataInfluenceDataSubsToNotifySubscriptionIdGet function in the UDR service includes a return statement after the 404 error response is sent.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40247
GHSA-X5R2-R74C-3W28
GO-2026-5741
OPENSUSE-SU-2026:21483-1

Affected Products

Free5Gc