PT-2026-45512 · Undefined · Undefined
Minamikotor1
+1
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-37233
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq xapp ric gen id() in src/ric/iApp/xapp ric id.c compares m0->xapp id against itself (m0->xapp id) instead of the other argument (m1->xapp id), effectively ignoring the xApp identity dimension. A malicious xApp connected to the iApp (port 36422) can delete any other xApp's subscriptions by sending an E42 RIC SUBSCRIPTION DELETE REQUEST with a matching ric gen id. This breaks multi-tenant isolation in any deployment with multiple xApps sharing the same RIC.
Exploit
Fix
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined