[{"data":1,"prerenderedAt":482},["ShallowReactive",2],{"news-articles":3},[4,256],{"_path":5,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":9,"description":10,"date":11,"author":12,"category":13,"tags":14,"body":21,"_type":250,"_id":251,"_source":252,"_file":253,"_stem":254,"_extension":255},"\u002Fnews\u002Fcve-2026-3gpp-sba-auth-bypass","news",false,"","Critical Advisory: HTTP\u002F2 NRF Authorization Flaws in 5G Standalone Deployments","Analysis of 5G Service-Based Architecture token validation vulnerabilities in Network Repository Functions (NRF) enabling unauthorized Network Function registration.","2026-09-18","TelcoSec Threat Research Team","5G Core Security",[15,16,17,18,19,20],"5G Core","NRF","OAuth2","3GPP","SBA","CVE-2026-8812",{"type":22,"children":23,"toc":243},"root",[24,32,75,82,110,116,129,138,151,157,218,224],{"type":25,"tag":26,"props":27,"children":29},"element","h1",{"id":28},"critical-advisory-http2-nrf-authorization-flaws-in-5g-standalone-deployments",[30],{"type":31,"value":9},"text",{"type":25,"tag":33,"props":34,"children":35},"p",{},[36,42,44,48,53,55,58,63,65,68,73],{"type":25,"tag":37,"props":38,"children":39},"strong",{},[40],{"type":31,"value":41},"Publication Date:",{"type":31,"value":43}," September 18, 2026",{"type":25,"tag":45,"props":46,"children":47},"br",{},[],{"type":25,"tag":37,"props":49,"children":50},{},[51],{"type":31,"value":52},"Author:",{"type":31,"value":54}," TelcoSec Threat Research Team",{"type":25,"tag":45,"props":56,"children":57},{},[],{"type":25,"tag":37,"props":59,"children":60},{},[61],{"type":31,"value":62},"Advisory ID:",{"type":31,"value":64}," TS-ADV-2026-004",{"type":25,"tag":45,"props":66,"children":67},{},[],{"type":25,"tag":37,"props":69,"children":70},{},[71],{"type":31,"value":72},"Impacted Protocols:",{"type":31,"value":74}," 3GPP TS 29.510 \u002F TS 33.501 (5G Service Based Architecture)",{"type":25,"tag":76,"props":77,"children":79},"h2",{"id":78},"executive-summary",[80],{"type":31,"value":81},"Executive Summary",{"type":25,"tag":33,"props":83,"children":84},{},[85,87,92,94,99,101,108],{"type":31,"value":86},"Security researchers at the ",{"type":25,"tag":37,"props":88,"children":89},{},[90],{"type":31,"value":91},"TelcoSec Research Group",{"type":31,"value":93}," have identified a critical authorization bypass pattern affecting early Release 16\u002F17 5G Standalone (SA) Core deployments. When Network Functions (NFs) register with the central ",{"type":25,"tag":37,"props":95,"children":96},{},[97],{"type":31,"value":98},"Network Repository Function (NRF)",{"type":31,"value":100}," via the ",{"type":25,"tag":102,"props":103,"children":105},"code",{"className":104},[],[106],{"type":31,"value":107},"nnrf-nfm",{"type":31,"value":109}," service, improper validation of OAuth2 JSON Web Tokens (JWT) allows rogue network elements to advertise themselves as authoritative AMFs or SMFs.",{"type":25,"tag":76,"props":111,"children":113},{"id":112},"technical-analysis",[114],{"type":31,"value":115},"Technical Analysis",{"type":25,"tag":33,"props":117,"children":118},{},[119,121,127],{"type":31,"value":120},"Under 3GPP specification TS 33.501, every NF discovery request across the Service-Based Interface (SBI) must be authorized by an access token issued by the NRF containing audience claims (",{"type":25,"tag":102,"props":122,"children":124},{"className":123},[],[125],{"type":31,"value":126},"aud",{"type":31,"value":128},") specifying the target NF type and NF instance ID.",{"type":25,"tag":130,"props":131,"children":133},"pre",{"code":132},"+----------------+      1. Discovery Request (No Token)       +----------------+\n|  Rogue 5G NF   | -----------------------------------------> |  5G NRF Node   |\n| (TelcoChisel)  | \u003C----------------------------------------- | (SBI Gateway)  |\n|                |      2. 200 OK with All Core Profiles      |                |\n+----------------+                                            +----------------+\n",[134],{"type":25,"tag":102,"props":135,"children":136},{"__ignoreMap":8},[137],{"type":31,"value":132},{"type":25,"tag":33,"props":139,"children":140},{},[141,143,149],{"type":31,"value":142},"When an operator misconfigures the NRF ",{"type":25,"tag":102,"props":144,"children":146},{"className":145},[],[147],{"type":31,"value":148},"service-authorization.strict-mode: false",{"type":31,"value":150}," fallback flag, the NRF accepts unsigned discovery queries, disclosing the full internal IP topology and cryptographic certificates of all active UDM, AUSF, and UPF instances.",{"type":25,"tag":76,"props":152,"children":154},{"id":153},"mitigation-remediation-guidelines",[155],{"type":31,"value":156},"Mitigation & Remediation Guidelines",{"type":25,"tag":158,"props":159,"children":160},"ol",{},[161,172,197],{"type":25,"tag":162,"props":163,"children":164},"li",{},[165,170],{"type":25,"tag":37,"props":166,"children":167},{},[168],{"type":31,"value":169},"Enforce Mutual TLS (mTLS)",{"type":31,"value":171},": Mandate strict bidirectional X.509 certificate validation across all N32 and SBI interfaces.",{"type":25,"tag":162,"props":173,"children":174},{},[175,180,182,187,189,195],{"type":25,"tag":37,"props":176,"children":177},{},[178],{"type":31,"value":179},"Strict Audience Checking",{"type":31,"value":181},": Validate ",{"type":25,"tag":102,"props":183,"children":185},{"className":184},[],[186],{"type":31,"value":126},{"type":31,"value":188}," and ",{"type":25,"tag":102,"props":190,"children":192},{"className":191},[],[193],{"type":31,"value":194},"scope",{"type":31,"value":196}," claims in every received JWT token at the target Service Producer.",{"type":25,"tag":162,"props":198,"children":199},{},[200,205,207],{"type":25,"tag":37,"props":201,"children":202},{},[203],{"type":31,"value":204},"Audit with TelcoChisel",{"type":31,"value":206},":\n",{"type":25,"tag":130,"props":208,"children":213},{"code":209,"language":210,"meta":8,"className":211},"# Run automated SBA OAuth2 token validation audit\ntelcochisel-5g-audit --nrf http:\u002F\u002F10.0.0.1:7777 --check-auth-bypass\n","bash",[212],"language-bash",[214],{"type":25,"tag":102,"props":215,"children":216},{"__ignoreMap":8},[217],{"type":31,"value":209},{"type":25,"tag":76,"props":219,"children":221},{"id":220},"hands-on-simulation",[222],{"type":31,"value":223},"Hands-on Simulation",{"type":25,"tag":33,"props":225,"children":226},{},[227,229,241],{"type":31,"value":228},"Operators and penetration testers can simulate this attack and test mitigation patches in the ",{"type":25,"tag":37,"props":230,"children":231},{},[232],{"type":25,"tag":233,"props":234,"children":238},"a",{"href":235,"rel":236},"https:\u002F\u002Fapp.telcosec.net",[237],"nofollow",[239],{"type":31,"value":240},"TelcoSec Academy 5G SBA Red Team Lab",{"type":31,"value":242},".",{"title":8,"searchDepth":244,"depth":244,"links":245},2,[246,247,248,249],{"id":78,"depth":244,"text":81},{"id":112,"depth":244,"text":115},{"id":153,"depth":244,"text":156},{"id":220,"depth":244,"text":223},"markdown","content:news:cve-2026-3gpp-sba-auth-bypass.md","content","news\u002Fcve-2026-3gpp-sba-auth-bypass.md","news\u002Fcve-2026-3gpp-sba-auth-bypass","md",{"_path":257,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":258,"description":259,"date":260,"author":12,"category":261,"tags":262,"body":268,"_type":250,"_id":479,"_source":252,"_file":480,"_stem":481,"_extension":255},"\u002Fnews\u002Fss7-location-tracking-carrier-advisory","SS7 Cross-Border Location Tracking Tactics Observed Against Tier-1 Operators","Detailed breakdown of sophisticated MAP ProvideSubscriberInfo and SendRoutingInfo attacks circumventing legacy STP SMS firewalls.","2026-09-10","SS7 \u002F SIGTRAN Security",[263,264,265,266,267],"SS7","MAP","Location Tracking","SIGTRAN","Interconnect",{"type":22,"children":269,"toc":473},[270,275,311,317,322,328,341,404,412,418,452,458],{"type":25,"tag":26,"props":271,"children":273},{"id":272},"ss7-cross-border-location-tracking-tactics-observed-against-tier-1-operators",[274],{"type":31,"value":258},{"type":25,"tag":33,"props":276,"children":277},{},[278,282,284,287,291,292,295,299,301,304,309],{"type":25,"tag":37,"props":279,"children":280},{},[281],{"type":31,"value":41},{"type":31,"value":283}," September 10, 2026",{"type":25,"tag":45,"props":285,"children":286},{},[],{"type":25,"tag":37,"props":288,"children":289},{},[290],{"type":31,"value":52},{"type":31,"value":54},{"type":25,"tag":45,"props":293,"children":294},{},[],{"type":25,"tag":37,"props":296,"children":297},{},[298],{"type":31,"value":62},{"type":31,"value":300}," TS-ADV-2026-003",{"type":25,"tag":45,"props":302,"children":303},{},[],{"type":25,"tag":37,"props":305,"children":306},{},[307],{"type":31,"value":308},"Target Protocols:",{"type":31,"value":310}," GSM MAP \u002F TCAP \u002F SCCP",{"type":25,"tag":76,"props":312,"children":314},{"id":313},"overview",[315],{"type":31,"value":316},"Overview",{"type":25,"tag":33,"props":318,"children":319},{},[320],{"type":31,"value":321},"Recent telemetry collected from international telecom signaling research nodes indicates a surge in categorized Category 1 & Category 2 GSMA FS.11 bypass maneuvers. Adversaries utilizing leased Global Title (GT) routes are chaining multiple MAP queries to bypass keyword-based signaling firewalls.",{"type":25,"tag":76,"props":323,"children":325},{"id":324},"attack-sequence-analysis",[326],{"type":31,"value":327},"Attack Sequence Analysis",{"type":25,"tag":33,"props":329,"children":330},{},[331,333,339],{"type":31,"value":332},"Rather than issuing single ",{"type":25,"tag":102,"props":334,"children":336},{"className":335},[],[337],{"type":31,"value":338},"AnyTimeInterrogation",{"type":31,"value":340}," (ATI) messages—which are commonly blocked by modern carrier STPs—attackers are staging queries in a three-phase reconnaissance cycle:",{"type":25,"tag":158,"props":342,"children":343},{},[344,362,372],{"type":25,"tag":162,"props":345,"children":346},{},[347,352,354,360],{"type":25,"tag":37,"props":348,"children":349},{},[350],{"type":31,"value":351},"Phase 1: IMSI Resolution",{"type":31,"value":353},": Sending ",{"type":25,"tag":102,"props":355,"children":357},{"className":356},[],[358],{"type":31,"value":359},"sendRoutingInfoForSM",{"type":31,"value":361}," (SRI-SM) with randomized SCCP Calling Party Addresses (CgPA) mimicking legitimate roaming SMS centers.",{"type":25,"tag":162,"props":363,"children":364},{},[365,370],{"type":25,"tag":37,"props":366,"children":367},{},[368],{"type":31,"value":369},"Phase 2: Serving MSC\u002FVLR Identification",{"type":31,"value":371},": Harvesting the target's current VLR address from the SRI-SM response.",{"type":25,"tag":162,"props":373,"children":374},{},[375,380,382,388,390,396,397,403],{"type":25,"tag":37,"props":376,"children":377},{},[378],{"type":31,"value":379},"Phase 3: Real-Time Cell ID Extraction",{"type":31,"value":381},": Directly querying the visited MSC using ",{"type":25,"tag":102,"props":383,"children":385},{"className":384},[],[386],{"type":31,"value":387},"provideSubscriberInfo",{"type":31,"value":389}," (PSI) requesting ",{"type":25,"tag":102,"props":391,"children":393},{"className":392},[],[394],{"type":31,"value":395},"locationInformation",{"type":31,"value":188},{"type":25,"tag":102,"props":398,"children":400},{"className":399},[],[401],{"type":31,"value":402},"ageOfLocationEstimate",{"type":31,"value":242},{"type":25,"tag":130,"props":405,"children":407},{"code":406},"Attacker (GT Leased) ----[ MAP SRI-SM ]----> Carrier HLR\nCarrier HLR        ----[ IMSI + VLR GT ]---> Attacker\nAttacker (GT Leased) ----[ MAP PSI ]-------> Visited MSC\u002FVLR\nVisited MSC\u002FVLR    ----[ CGI (Cell ID) ]---> Attacker (Location Fixed)\n",[408],{"type":25,"tag":102,"props":409,"children":410},{"__ignoreMap":8},[411],{"type":31,"value":406},{"type":25,"tag":76,"props":413,"children":415},{"id":414},"recommended-defense-configuration",[416],{"type":31,"value":417},"Recommended Defense Configuration",{"type":25,"tag":419,"props":420,"children":421},"ul",{},[422,427,432],{"type":25,"tag":162,"props":423,"children":424},{},[425],{"type":31,"value":426},"Implement GSMA FS.11 Cat 1\u002F2\u002F3 multi-layer filtering at all international STP \u002F ITP edge gateways.",{"type":25,"tag":162,"props":428,"children":429},{},[430],{"type":31,"value":431},"Enforce strict MAP screening for PSI messages arriving from international interconnect links (PSI should never originate outside the subscriber's home network).",{"type":25,"tag":162,"props":433,"children":434},{},[435,437,443,444,450],{"type":31,"value":436},"Utilize TelcoChisel's ",{"type":25,"tag":102,"props":438,"children":440},{"className":439},[],[441],{"type":31,"value":442},"sigploit",{"type":31,"value":188},{"type":25,"tag":102,"props":445,"children":447},{"className":446},[],[448],{"type":31,"value":449},"sctpscan",{"type":31,"value":451}," to continuously validate interconnect firewall policy rules.",{"type":25,"tag":76,"props":453,"children":455},{"id":454},"educational-lab-access",[456],{"type":31,"value":457},"Educational Lab Access",{"type":25,"tag":33,"props":459,"children":460},{},[461,463,472],{"type":31,"value":462},"Full packet traces and emulation scripts are available inside the ",{"type":25,"tag":37,"props":464,"children":465},{},[466],{"type":25,"tag":233,"props":467,"children":469},{"href":235,"rel":468},[237],[470],{"type":31,"value":471},"TelcoSec Academy Signaling Security Module",{"type":31,"value":242},{"title":8,"searchDepth":244,"depth":244,"links":474},[475,476,477,478],{"id":313,"depth":244,"text":316},{"id":324,"depth":244,"text":327},{"id":414,"depth":244,"text":417},{"id":454,"depth":244,"text":457},"content:news:ss7-location-tracking-carrier-advisory.md","news\u002Fss7-location-tracking-carrier-advisory.md","news\u002Fss7-location-tracking-carrier-advisory",1790363494234]