PT-2026-45512 · Undefined · Undefined

Minamikotor1

+1

·

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-37233

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq xapp ric gen id() in src/ric/iApp/xapp ric id.c compares m0->xapp id against itself (m0->xapp id) instead of the other argument (m1->xapp id), effectively ignoring the xApp identity dimension. A malicious xApp connected to the iApp (port 36422) can delete any other xApp's subscriptions by sending an E42 RIC SUBSCRIPTION DELETE REQUEST with a matching ric gen id. This breaks multi-tenant isolation in any deployment with multiple xApps sharing the same RIC.

Exploit

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-37233

Affected Products

Undefined