Junglewise Threat Intelligence

CVE-2025-66719: Free5gc NRF scope validation bypass in access-token generation

CVE-2025-66719 · Severity: critical · CVSS 9.1 · Published 2026-01-23

Executive brief

Free5gc NRF, a core component of 5G mobile networks used for managing network functions, contains a security flaw in how it validates access requests. An attacker can bypass security checks by providing a specially crafted value, allowing them to obtain unauthorized access tokens. This could lead to unauthorized control over network services and potential exposure of sensitive mobile network data.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Free5gc NRF version 1.4.0. The AccessTokenScopeCheck() function within internal/sbi/processor/access_token.go fails to properly validate scopes when a maliciously crafted targetNF value is provided. A remote, unauthenticated attacker can exploit this over the network to bypass all scope validation logic. Successful exploitation allows the attacker to generate access tokens with any arbitrary scope, leading to a complete compromise of confidentiality and integrity within the affected 5G core network environment. The issue is addressed in version 1.4.1.

Affected products

  • Free5gc NRF 1.4.0

Timeline

  • 2026-01-23: disclosed
  • 2026-01-23: advisory
  • 2026-06-05: patched: Advisory updated to reflect patch in 1.4.1

References

Related threats