|
91
|
10.0 |
CRITICAL
Network
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanagement route group without inbound OAuth2/bearer-token authorization. A network a…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-44330
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
92
|
10.0 |
CRITICAL
Network
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. A network at…
New
|
CWE-306 CWE-862
Missing Authentication for Critical Function Missing Authorization
|
CVE-2026-44329
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
93
|
8.2 |
HIGH
Network
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of that, the DELETE /upi…
New
|
CWE-306 CWE-476 CWE-862
Missing Authentication for Critical Function NULL Pointer Dereference Missing Authorization
|
CVE-2026-44328
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
94
|
10.0 |
CRITICAL
Network
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker wh…
New
|
CWE-306 CWE-862
Missing Authentication for Critical Function Missing Authorization
|
CVE-2026-44327
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
95
|
9.4 |
CRITICAL
Network
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attac…
New
|
CWE-862
Missing Authorization
|
CVE-2026-44326
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
96
|
7.5 |
HIGH
Network
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug family. The handler in N…
New
|
CWE-20 CWE-755 CWE-843
Improper Input Validation Improper Handling of Exceptional Conditions Type Confusion
|
CVE-2026-44325
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
97
|
6.5 |
MEDIUM
Network
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions han…
New
|
CWE-704 CWE-754
Incorrect Type Conversion or Cast Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-44324
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
98
|
4.3 |
MEDIUM
Network
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions han…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-44323
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
99
|
7.5 |
HIGH
Network
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler panics with a n…
New
|
CWE-476 CWE-754
NULL Pointer Dereference Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-44322
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
100
|
7.5 |
HIGH
Network
|
-
|
-
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. The POST /upi/v1/upNodesLinks c…
New
|
CWE-306 CWE-617 CWE-862
Missing Authentication for Critical Function Reachable Assertion Missing Authorization
|
CVE-2026-44321
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|