CVE-2026-40247: free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions
(updated )
An improper path validation vulnerability in the UDR service allows any unauthenticated attacker with access to the 5G Service Based Interface (SBI) to read Traffic Influence Subscriptions by supplying an arbitrary value in place of the expected subs-to-notify path segment.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-40247 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →