{"id":"GHSA-6rgm-gr97-x3j5","summary":"Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI","details":"### Summary\nPCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI\n### Details\nIn `NewServer()`, the `smPolicyGroup` route group is created and routes are applied without attaching the router authorization middleware. In contrast, other PCF service groups such as `Npcf_PolicyAuthorization` do attach `RouterAuthorizationCheck` before route registration.\n\nBecause the middleware is missing, requests to the following endpoints can reach business logic even when no valid OAuth token is provided:\n\n- `POST /npcf-smpolicycontrol/v1/sm-policies`\n- `GET /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}`\n- `POST /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/update`\n- `POST /npcf-smpolicycontrol/v1/sm-policies/{smPolicyId}/delete`\n\nThis is visible at runtime because unauthenticated requests return business-level responses such as `400` or `404` instead of being rejected with `401` before handler execution. Under valid lab preconditions (existing UE/session context and related policy data), unauthenticated `POST /sm-policies` can succeed with `201`, and unauthenticated `GET /sm-policies/{id}` can succeed with `200` and return policy context containing subscriber identifiers including `supi`.\n\nThe root cause is missing router auth enforcement for `Npcf_SMPolicyControl`. \nUpstream also fixed this by adding `RouterAuthorizationCheck` to `smPolicyGroup` (and `uePolicyGroup`) in free5gc/pcf PR #63.\n\n### PoC\n1. Deploy free5GC with PCF reachable on the SBI network.\n2. Use the PoC against the PCF service **without** an `Authorization` header:\n   ```bash\n   go run /home/ubuntu/free5gc/tools/npcf-smpolicy-noauth-poc/main.go \\\n     --pcf-root /home/ubuntu/free5gc/NFs/pcf \\\n     --pcf-url http://10.100.200.9:8000 \\\n     --timeout 4s\nObserve that unauthenticated requests to Npcf_SMPolicyControl return business responses instead of 401.\n### Impact\n\nThis is an authentication/authorization bypass on a network-accessible SBI service. Any unauthenticated actor able to reach the PCF SBI interface can invoke Npcf_SMPolicyControl handlers directly.","aliases":["CVE-2026-42083","GO-2026-5189"],"modified":"2026-06-25T19:56:23.810418766Z","published":"2026-05-07T01:58:42Z","database_specific":{"cwe_ids":["CWE-862"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-05-07T01:58:42Z","nvd_published_at":"2026-05-27T17:16:35Z"},"references":[{"type":"WEB","url":"https://github.com/free5gc/free5gc/security/advisories/GHSA-6rgm-gr97-x3j5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42083"},{"type":"WEB","url":"https://github.com/free5gc/free5gc/issues/844"},{"type":"WEB","url":"https://github.com/free5gc/pcf/pull/63"},{"type":"WEB","url":"https://github.com/free5gc/pcf/commit/8c4d457cdf58bb239ee30e88c56b370b22073964"},{"type":"PACKAGE","url":"https://github.com/free5gc/free5gc"}],"affected":[{"package":{"name":"github.com/free5gc/pcf","ecosystem":"Go","purl":"pkg:golang/github.com/free5gc/pcf"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-6rgm-gr97-x3j5/GHSA-6rgm-gr97-x3j5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}