10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
Description
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on the SBI can hit UPI endpoints with no Authorization header at all, and the requests reach the SMF business handlers. In the running Docker lab this was directly demonstrated for read (GET /upi/v1/upNodesLinks), write (POST /upi/v1/upNodesLinks with attacker-controlled UP-node and link payload), and delete (DELETE /upi/v1/upNodesLinks/{nodeID}) operations. This vulnerability is fixed in 4.2.2.
AI Analysis
Unauthenticated access to UPI management interface due to missing OAuth2/bearer-token authorization middleware, allowing read, write, and delete operations.
Basic Information
ID
CVE-2026-44329
Source
GitHub_M
Published
May 27, 2026 at 15:38
Affected Product
Vendor
free5gc
Product
free5gc
Version
< 4.2.2
Affected Versions
free5gc free5gc < 4.2.2
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
free5gc
Product
free5GC
Version
< 4.2.2