CVE 10 CRITICAL

free5GC: SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlers_CVE-2026-44329

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

Description

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on the SBI can hit UPI endpoints with no Authorization header at all, and the requests reach the SMF business handlers. In the running Docker lab this was directly demonstrated for read (GET /upi/v1/upNodesLinks), write (POST /upi/v1/upNodesLinks with attacker-controlled UP-node and link payload), and delete (DELETE /upi/v1/upNodesLinks/{nodeID}) operations. This vulnerability is fixed in 4.2.2.

AI Analysis

Unauthenticated access to UPI management interface due to missing OAuth2/bearer-token authorization middleware, allowing read, write, and delete operations.

Basic Information

ID CVE-2026-44329
Source GitHub_M
Published May 27, 2026 at 15:38

Affected Product

Vendor free5gc
Product free5gc
Version < 4.2.2
Affected Versions free5gc free5gc < 4.2.2

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor free5gc
Product free5GC
Version < 4.2.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.