PT-2026-82532 · Free5Gc · Free5Gc

·

CVE-2026-30068

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions free5gc version 4.0.1
Description Improper input validation in the HandleUpdate() function located in /sbi/parameter provision.go allows attackers to cause a Denial of Service (DoS), a condition where the service becomes unavailable to its intended users, by providing a crafted input.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the HandleUpdate() function to minimize the risk of exploitation.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30068

Affected Products

Free5Gc