PT-2026-4469 · Unknown · Free5Gc Nrf
Published
2026-01-23
·
Updated
2026-02-11
·
CVE-2025-66719
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Free5gc NRF version 1.4.0
Description
An issue exists in the access-token generation logic of Free5gc. The
AccessTokenScopeCheck() function within the file internal/sbi/processor/access token.go bypasses scope validation when a crafted targetNF value is used. This allows an attacker to obtain an access token with any arbitrary scope.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting or carefully validating the
targetNF value used in the access token generation process.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Free5Gc Nrf