Information Disclosure in free5GC UDR Service from Vendor free5GC
CVE-2026-40247

8.7HIGH

Key Information:

Vendor

Free5gc

Status
Vendor
CVE Published:
16 April 2026

What is CVE-2026-40247?

The UDR service in free5GC, an open-source implementation of the 5G core network, exhibits a vulnerability that allows unauthenticated attackers to access sensitive subscription data. Specifically, in versions 4.2.1 and earlier, the application fails to terminate a session upon receiving an invalid influenceId within its Traffic Influence Subscriptions handler. As a result, critical data, including Subscriber Permanent Identifiers (SUPIs), International Mobile Subscriber Identities (IMSIs), Data Network Names (DNNs), and callback URIs, can be revealed despite the initial 404 error response. This issue poses substantial risks to the integrity and confidentiality of user data in 5G services. A fix for this vulnerability was not available at the time of reporting.

Affected Version(s)

free5gc <= 1.4.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.