


Perceptive Security
SOC/SIEM Consultancy

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/beare…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 20:13:41
Source:
nvd.nist.gov
Network Infrastructure, Critical Infrastructure, Mobile & IoT
CVE-2026-44320 affects free5GC, an open-source 5G core network implementation. Prior to version 4.2.2, the NEF component mounts the nnef-callback route group without proper OAuth2/bearer-token authorization. Attackers can use forged bearer tokens to reach the SMF-callback handler and process malicious callbacks. The vulnerability allows bypass of authentication boundaries and manipulation of subscription state if a valid NotifId is obtained. The route group remains accessible even when not declared in the runtime ServiceList. This represents a critical authentication bypass in 5G network infrastructure. The vulnerability has been fixed in version 4.2.2.
Technical details
Mitigation steps:
Affected products:
free5GC
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44320
https://github.com/free5gc/free5gc/issues/860
https://github.com/free5gc/free5gc/security/advisories/GHSA-wqfh-gq79-j8mf
https://github.com/free5gc/nef/pull/24
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
