Vulnerability Description
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no Authorization header at all and the handler returns 200 OK. The current OAM handler is a stub that returns null, but the structural defect is route-group-scoped: the entire OAM route group has no inbound auth middleware, so every future OAM operation added to this group inherits the missing auth boundary by default. This vulnerability is fixed in 4.2.2.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Free5Gc | Free5Gc | < 4.2.2 |
Related Weaknesses (CWE)
References
- https://github.com/free5gc/free5gc/issues/861ExploitIssue Tracking
- https://github.com/free5gc/free5gc/security/advisories/GHSA-cmpj-2x3g-m7g3ExploitVendor Advisory
- https://github.com/free5gc/nef/pull/23Issue TrackingPatch
- https://github.com/free5gc/free5gc/security/advisories/GHSA-cmpj-2x3g-m7g3ExploitVendor Advisory
FAQ
What is CVE-2026-44327?
CVE-2026-44327 is a vulnerability with a CVSS score of 10.0 (CRITICAL). free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who...
How severe is CVE-2026-44327?
CVE-2026-44327 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-44327?
Check the references section above for vendor advisories and patch information. Affected products include: Free5Gc Free5Gc.