CRITICAL🇵🇱 Wersja polska

CVE-2026-44326

CVSS 9.4v3.1pub. 2026-05-27upd. 2026-05-28

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, patch, and delete traffic-influence subscriptions either with no Authorization header at all, or with a forged bearer token (e.g. Authorization: Bearer not-a-real-token). This includes creating AnyUeInd=true subscriptions intended to affect group / any-UE traffic steering. The route group is also reachable even when the running config's ServiceList does not declare it, so operators who think they disabled the service via config are still exposed. This vulnerability is fixed in 4.2.2.

🤖 AI Analysis
How it works

The NEF (Network Exposure Function) component in free5GC mounts a routing group for the 3gpp-traffic-influence API without Authorization header verification — both requests without any token and requests with arbitrarily fabricated bearer tokens are accepted. Moreover, the vulnerable routing group remains available even if the operator disabled the service in the configuration (ServiceList), making administrative disabling ineffective. An attacker can thereby create, read, modify, and delete traffic-influence subscriptions, including subscriptions with the AnyUeInd=true flag affecting all traffic of a group or any UE.

Impact

An attacker can seize control over traffic control policies in the 5G network — by creating, modifying, or deleting traffic-influence subscriptions, they can disrupt or redirect traffic of all network users (AnyUeInd=true), leading to loss of integrity and availability of network services. Unauthorized reading of subscription data is also possible.

Mitigation & patch

Update free5GC to version 4.2.2 or later, in which the fix has been implemented. Details are available in the official security advisory from the vendor and pull request #23 in the free5gc/nef repository.

Who is affected

free5GC (open-source implementation of 5G core network) in versions prior to 4.2.2 — NEF (Network Exposure Function) component.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
  • Free5gc

    APP
    Free5Gc
    < 4.2.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-44330CRITICAL10.0PL ✓same product

free5GC NEF: brak autoryzacji OAuth2 na trasach nnef-pfdmanagement

CVE-2026-44329CRITICAL10.0PL ✓same product

free5GC SMF: brak autoryzacji OAuth2 na endpointach UPI — pełny dostęp bez uwierzytelnienia

CVE-2026-44327CRITICAL10.0PL ✓same product

Brak autoryzacji OAuth2 w grupie tras OAM w free5GC NEF (5G core)

CVE-2026-44315CRITICAL9.4PL ✓same product

Brak autoryzacji OAuth2 w NEF API sieci 5G (free5GC)

CVE-2023-4659CRITICAL9.8PL ✓same product

CSRF w Free5GC umożliwia nieautoryzowane zarządzanie użytkownikami