๐Ÿ” CVE Alert

CVE-2026-44320

HIGH 7.3

free5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing path

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorization. A forged or arbitrary bearer token (e.g. Authorization: Bearer not-a-real-token) is enough to reach the SMF-callback handler -- the callback body is parsed and dispatched into NEF business logic instead of being rejected at the auth boundary. Same root cause as the other NEF SBI findings: the route group is mounted without any inbound auth middleware. NEF does not authenticate the producer NF identity before processing callback content; if an attacker can guess or obtain a valid NotifId, this missing auth boundary lets forged callbacks act on real subscription state. The route group is also reachable even when the runtime ServiceList does not declare it (it lists only nnef-pfdmanagement and nnef-oam). This vulnerability is fixed in 4.2.2.

CWE CWE-306 CWE-862
Vendor free5gc
Product free5gc
Published May 27, 2026
Last Updated May 27, 2026
Stay Ahead of the Next One

Get instant alerts for free5gc free5gc

Be the first to know when new high vulnerabilities affecting free5gc free5gc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

free5gc / free5gc
< 4.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/free5gc/free5gc/security/advisories/GHSA-wqfh-gq79-j8mf github.com: https://github.com/free5gc/free5gc/issues/860 github.com: https://github.com/free5gc/nef/pull/24