CVE 9.4 CRITICAL

free5GC: NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete subscriptions_CVE-2026-44326

9.4 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Description

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, patch, and delete traffic-influence subscriptions either with no Authorization header at all, or with a forged bearer token (e.g. Authorization: Bearer not-a-real-token). This includes creating AnyUeInd=true subscriptions intended to affect group / any-UE traffic steering. The route group is also reachable even when the running config's ServiceList does not declare it, so operators who think they disabled the service via config are still exposed. This vulnerability is fixed in 4.2.2.

AI Analysis

Unauthenticated NEF 3gpp-traffic-influence API allows creation, reading, patching, and deletion of subscriptions due to missing or forged bearer tokens

Basic Information

ID CVE-2026-44326
Source GitHub_M
Published May 27, 2026 at 15:41

Affected Product

Vendor free5gc
Product free5gc
Version < 4.2.2
Affected Versions free5gc free5gc < 4.2.2

CWE Classification

AI Assessment

AI Score 9.4 / 10
AI Severity Critical
Vendor free5GC
Product free5GC
Version < 4.2.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.