Critical Vulnerability in free5GC Exposes 5G Core Network to Attacks

Critical Vulnerability in free5GC Exposes 5G Core Network to Attacks

First seen 29 Aug 2026, 13:49 UTC Feedlystemshop.topcve.reportadvisories.gitlab.comvuldb.com 70.5

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-55068, has been identified in the free5GC open-source implementation of the 5G core network. The flaw exists in versions 4.2.2 and earlier, where the NRF RegisterNFInstance handler fails to validate NF Profiles properly. This allows attackers with SBI access to submit invalid profiles, potentially redirecting control-plane signaling and exposing sensitive credentials. The vulnerability has a CVSS score of 9.3, indicating a high level of severity. It can lead to service denial and integrity issues across network functions that trust the NRF. The issue has been addressed in version 4.2.3, which is now available. Currently, there are no public proof-of-concept exploits reported. The vulnerability was published on August 28, 2026, and is considered critical due to its potential impact on network security.

Key Points: • CVE-2026-55068 has a CVSS score of 9.3, indicating critical severity. • The vulnerability allows attackers to exploit improperly validated NF Profiles in free5GC. • Version 4.2.3 has been released to address this vulnerability.

Timeline

2026-08-28
CVE-2026-55068 published
The vulnerability was officially published, detailing flaws in free5GC's NRF RegisterNFInstance handler.
stemshop.top
2026-08-29
Critical vulnerability reported
Multiple outlets reported on the critical nature of CVE-2026-55068 and its implications for 5G networks.
Feedly
2026-08-29
Patch released
Version 4.2.3 of free5GC was released to fix the vulnerability, urging users to update.
stemshop.top