CVE-2026-44327Critical· 10.0▾ Midnightfree5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.5%
free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no Authorization header at all and the handler returns 200 OK. The current OAM handler is a stub that returns null, but the structural defect is route-group-scoped: the entire OAM route group has no inbound auth middleware, so every future OAM operation added to this group inherits the missing auth boundary by default. Same root cause as the NEF traffic-influence and PFD-management findings.
Validated against the NEF container in the official Docker compose lab.
v4.2.1free5gc/nef:v4.2.05ce35eabNEF advertises OAuth2 setting receive from NRF: true, yet the OAM route group is mounted without any inbound auth middleware and answers unauthenticated GETs with 200 OK.
Code evidence (paths in free5gc/nef):
NFs/nef/internal/sbi/server.go:60/: NFs/nef/internal/sbi/api_oam.go:9200 OK directly: NFs/nef/internal/sbi/processor/oam.go:9GetTokenCtx); there is no inbound authorization path: NFs/nef/internal/context/nef_context.go:153Reproduced against the running NEF at http://10.100.200.19:8000 with no Authorization header:
curl -i http://10.100.200.19:8000/nnef-oam/v1/
Observed output:
HTTP/1.1 200 OK
null
NEF container logs (docker logs nef) show the request being served while OAuth is enabled:
[INFO][NEF][GIN] | 200 | GET | /nnef-oam/v1/
Missing inbound authentication (CWE-306) and authorization (CWE-862) on the NEF OAM SBI route group. Severity is scored against the OAM route group's intended capability surface (Operations / Administration / Maintenance), NOT against the current stub handler. The current handler is a stub that returns null, but the defect is route-group-scoped: there is no auth middleware on the group at all, so every future OAM operation added behind this group inherits the missing inbound auth boundary by default.
Any party that can reach NEF on the SBI can:
Operators who assume OAuth2 setting receive from NRF: true enforces inbound auth on NEF are wrong for this route group.
Affected: free5gc v4.2.1.
Upstream issue: https://github.com/free5gc/free5gc/issues/861 Upstream fix: https://github.com/free5gc/nef/pull/23
github.com/free5gc/nef <= 1.2.3Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40246High· 7.5free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
CVE-2025-66719Critical· 9.1Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value
CVE-2026-55785Low· 3.7free5GC is an open-source implementation of the 5G core network
CVE-2026-55784High· 7.5free5GC is an open-source implementation of the 5G core network
CVE-2026-55068Criticalfree5GC is an open-source implementation of the 5G core network
CVE-2026-53551Mediumfree5GC is an open-source implementation of the 5G core network