CVE 9.4 CRITICAL

free5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactions_CVE-2026-44315

9.4 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Description

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, and delete PFD-management transaction state with a forged or arbitrary bearer token (e.g. Authorization: Bearer not-a-real-token). The route group is also reachable even when the running config's ServiceList does not declare it, so operators who think they disabled the service via config are still exposed. This vulnerability is fixed in 4.2.2.

AI Analysis

Unauthenticated NEF 3gpp-pfd-management API allows creation, read, and deletion of PFD transactions with forged bearer tokens

Basic Information

ID CVE-2026-44315
Source GitHub_M
Published May 27, 2026 at 15:52

Affected Product

Vendor free5gc
Product free5gc
Version < 4.2.2
Affected Versions free5gc free5gc < 4.2.2

CWE Classification

AI Assessment

AI Score 9.4 / 10
AI Severity Critical
Vendor free5GC
Product free5GC
Version < 4.2.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.