{"id":"CVE-2026-42083","aliases":["GHSA-6rgm-gr97-x3j5","GO-2026-5189"],"url":"https://o3.security/vulnerability/CVE-2026-42083","summary":"free5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI","details":"### Summary\nPCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI\n### Details\nIn `NewServer()`, the `smPolicyGroup` route group is created and routes are applied without attaching the router authorization middleware. In contrast, other PCF service groups such as `Npcf_PolicyAuthorization` do attach `RouterAuthorizationCheck` before route registration.\n\nBecause the middleware is missing, requests to the following endpoints can reach business logic even when no valid OAuth token is provided:\n\n- `POST /npcf-smpolicycontrol/v1/sm-policies`\n- `GET /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}`\n- `POST /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/update`\n- `POST /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/delete`\n\nThis is visible at runtime because unauthenticated requests return business-level responses such as `400` or `404` instead of being rejected with `401` before handler execution. Under valid lab preconditions (existing UE/session context and related policy data), unauthenticated `POST /sm-policies` can succeed with `201`, and unauthenticated `GET /sm-policies/{id}` can succeed with `200` and return policy context containing subscriber identifiers including `supi`.\n\nThe root cause is missing router auth enforcement for `Npcf_SMPolicyControl`. \nUpstream also fixed this by adding `RouterAuthorizationCheck` to `smPolicyGroup` (and `uePolicyGroup`) in free5gc/pcf PR #63.\n\n### PoC\n1. Deploy free5GC with PCF reachable on the SBI network.\n2. Use the PoC against the PCF service **without** an `Authorization` header:\n   ```bash\n   go run /home/ubuntu/free5gc/tools/npcf-smpolicy-noauth-poc/main.go \\\n     --pcf-root /home/ubuntu/free5gc/NFs/pcf \\\n     --pcf-url http://10.100.200.9:8000 \\\n     --timeout 4s\nObserve that unauthenticated requests to Npcf_SMPolicyControl return business responses instead of 401.\n### Impact\n\nThis is an authentication/authorization bypass on a network-accessible SBI service. Any unauthenticated actor able to reach the PCF SBI interface can invoke Npcf_SMPolicyControl handlers directly.","published":"2026-05-27T15:56:11.394Z","modified":"2026-09-04T03:46:01.160316060Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"},"epss":{"score":0.00323,"percentile":0.25144,"asOf":"2026-09-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/free5gc/pcf","fixedVersion":"1.4.3"}],"fix":{"url":"https://github.com/free5gc/pcf/commit/8c4d457cdf58bb239ee30e88c56b370b22073964","label":"free5gc/pcf@8c4d457"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42083.json"},{"type":"ADVISORY","url":"https://github.com/free5gc/free5gc/security/advisories/GHSA-6rgm-gr97-x3j5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42083"},{"type":"REPORT","url":"https://github.com/free5gc/free5gc/issues/844"},{"type":"FIX","url":"https://github.com/free5gc/pcf/commit/8c4d457cdf58bb239ee30e88c56b370b22073964"},{"type":"FIX","url":"https://github.com/free5gc/pcf/pull/63"},{"type":"PACKAGE","url":"https://github.com/free5gc/free5gc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T03:46:01.160316060Z"}}