CVE-2025-66719Critical· 9.1▾ MidnightFree5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.4%
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the attacker uses a crafted targetNF value. This allows attackers to obtain an access token with any arbitrary scope.
github.com/free5gc/nrf < 1.4.1Upgrade to a patched release:
github.com/free5gc/nrf 1.4.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40246High· 7.5free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
CVE-2026-44327Critical· 10.0free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
CVE-2026-55785Low· 3.7free5GC is an open-source implementation of the 5G core network
CVE-2026-55784High· 7.5free5GC is an open-source implementation of the 5G core network
CVE-2026-55068Criticalfree5GC is an open-source implementation of the 5G core network
CVE-2026-53551Mediumfree5GC is an open-source implementation of the 5G core network