CVE-2026-40249 is a flaw in free5GC version 4.2.1 and below affecting the UDR (User Data Repository) service. The vulnerability exists in the PUT handler for Policy Data notification subscription updates, where error handling fails to prevent continued execution after request body retrieval or deserialization errors, creating a fail-open condition that may allow unauthorized modification of subscriptions with invalid input. The vulnerability carries a CVSS 3.1 score of 5.3 (Medium severity) with network-based attack vector, low complexity, and no authentication required. The primary impact is integrity-based, allowing potential modification of Policy Data notification subscriptions, while confidentiality and availability are not affected. The attack surface is broad given the network accessibility of the affected endpoint. There is no evidence of active exploitation in the wild, as the CVE is not listed on the Known Exploited Vulnerabilities catalog and the EPSS score of 0.0002 indicates minimal real-world exploitation activity. No public exploit code or detailed proof-of-concept materials appear to have generated significant community attention, though the vulnerability warrants patching once remediation becomes available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.1CPE matchmatch criteria | cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.