Critical Vulnerability in free5GC Exposes 5G Core Network to Attacks
ID: 06125294-e3b9-5c6f-8cbe-732663fc7cef
STIX ID: report--06125294-e3b9-5c6f-8cbe-732663fc7cef
Feed Name: ThreatCluster
Threat Score
A critical vulnerability (CVE-2026-55068, CVSS 9.3) was disclosed in free5GC (<= 4.2.2) where improper validation of NF Profiles in the NRF RegisterNFInstance handler allows attackers with SBI access to submit invalid profiles, potentially redirecting control-plane signaling, exposing sensitive credentials, and causing service denial or integrity issues; the issue was fixed in version 4.2.3 and no public proof-of-concept exploits were reported as of 2026-08-28.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
