Critical Vulnerability in free5GC Exposes 5G Core Network to Attacks
Article Content
A critical vulnerability, CVE-2026-55068, has been identified in the free5GC open-source implementation of the 5G core network. The flaw exists in versions 4.2.2 and earlier, where the NRF RegisterNFInstance handler fails to validate NF Profiles properly. This allows attackers with SBI access to submit invalid profiles, potentially redirecting control-plane signaling and exposing sensitive credentials. The vulnerability has a CVSS score of 9.3, indicating a high level of severity. It can lead to service denial and integrity issues across network functions that trust the NRF. The issue has been addressed in version 4.2.3, which is now available. Currently, there are no public proof-of-concept exploits reported. The vulnerability was published on August 28, 2026, and is considered critical due to its potential impact on network security.
Key Points: • CVE-2026-55068 has a CVSS score of 9.3, indicating critical severity. • The vulnerability allows attackers to exploit improperly validated NF Profiles in free5GC. • Version 4.2.3 has been released to address this vulnerability.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.