CVE-2026-44327
📛 CVE Title
(no title)
Description
free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
Description (MITRE) cveawg.mitre.org
Pulled from cveawg.mitre.org/api/cve/CVE-2026-44327 on 2026-07-27. Shown when MITRE's text differs from the cvelistV5 mirror.
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no Authorization header at all and the handler returns 200 OK. The current OAM handler is a stub that returns null, but the structural defect is route-group-scoped: the entire OAM route group has no inbound auth middleware, so every future OAM operation added to this group inherits the missing auth boundary by default. This vulnerability is fixed in 4.2.2.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- critical
- CVSS score
- 9.7 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H- Effective score
- 9.7 / 10 CRITICAL source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-44327
- Linked Threat
- CVE-2026-44327 — CVE-2026-44327
NVD / KEV / EPSS data refreshed 2026-05-24 23:56 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32571
EUVD enrichment is queued; refresh the page in a few seconds.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (6)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/free5gc/free5gc/issues/861 tenable:github.com
- https://github.com/free5gc/free5gc/security/advisories/GHSA-cmpj-2x3g-m7g3 tenable:github.com
- https://github.com/free5gc/nef/pull/23 tenable:github.com
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-44327 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-44327 tenable:www.cve.org
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:aviatrix.ai
The disclosure underscores the persistent targeting of Fortinet products by threat actors, often leveraging such vulnerabilities in ransomware and cyber-espionage campaigns. This incident highlights the critical importance of timely patch management and continuous monitoring to defend against evolving cyber threats.
2026-05-26 02:49 UTC -
web:blog.qualys.com
April 2026's Patch Tuesday arrives with Microsoft addressing a fresh set of vulnerabilities across its ecosystem, reinforcing the ongoing need for timely patching in an increasingly threat-heavy…
2026-05-26 02:49 UTC -
web:integsec.com
CVE‑2026‑44277 is a critical remote code execution flaw in Fortinet FortiAuthenticator that allows unauthenticated attackers to take full control of the appliance. Any organization using affected FortiAuthenticator versions must patch immediately or otherwise secure the appliance to prevent attackers from compromising identity and access management. Exposure to this vulnerability can lead ...
2026-05-26 02:49 UTC -
web:krebsonsecurity.com
For a clickable, per- patch breakdown, check out the SANS Internet Storm Center Patch Tuesday roundup. Running into problems applying any of these updates?
2026-05-26 02:49 UTC -
web:thewincentral.com
April 2026 Windows update causes LSASS crashes and reboot loops on domain controllers. Microsoft is working on a fix . - Read in Latest News on WinCentral
2026-05-26 02:49 UTC -
web:threatprotect.qualys.com
Zero-day Vulnerabilities Patched in April Patch Tuesday Edition CVE - 2026 -33825: Microsoft Defender Elevation of Privilege Vulnerability Microsoft Defender is a comprehensive, AI-powered security suite that provides malware protection, phishing detection, and web protection for individuals and businesses.
2026-05-26 02:49 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.
2026-05-26 02:49 UTC -
web:www.crowdstrike.com
Microsoft has released security updates for 130 vulnerabilities, including 30 critical, in its May 2026 Patch Tuesday rollout.
2026-05-26 02:49 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-26 02:49 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-26 02:49 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.