PT-2026-39256 · Free5Gc+1 · Free5Gc+1

Linziyuu

·

Published

2026-05-08

·

Updated

2026-05-27

·

CVE-2026-44326

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions free5GC versions prior to 4.2.2
Description The Network Exposure Function (NEF) mounts the '3gpp-traffic-influence' API without requiring inbound OAuth2 or bearer-token authorization. A network attacker with access to the NEF on the Service Based Interface (SBI) can perform create, read, patch, and delete operations on traffic-influence subscriptions. This can be achieved by omitting the Authorization header entirely or by using a forged bearer token. This allows for the creation of AnyUeInd=true subscriptions to affect group or any-UE traffic steering. Additionally, the route group remains reachable even if the ServiceList in the running configuration does not declare it, meaning operators cannot disable the service via configuration to mitigate the risk.
Recommendations Update to version 4.2.2.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44326
GHSA-3P28-73Q7-45XP

Affected Products

Free5Gc
Github.Com/Free5Gc/Nef