[{"data":1,"prerenderedAt":424},["ShallowReactive",2],{"news-doc-cve-2026-3gpp-sba-auth-bypass":3,"content-query-pA0Nlcsj4W":255},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"date":10,"author":11,"category":12,"tags":13,"body":20,"_type":249,"_id":250,"_source":251,"_file":252,"_stem":253,"_extension":254},"\u002Fnews\u002Fcve-2026-3gpp-sba-auth-bypass","news",false,"","Critical Advisory: HTTP\u002F2 NRF Authorization Flaws in 5G Standalone Deployments","Analysis of 5G Service-Based Architecture token validation vulnerabilities in Network Repository Functions (NRF) enabling unauthorized Network Function registration.","2026-09-18","TelcoSec Threat Research Team","5G Core Security",[14,15,16,17,18,19],"5G Core","NRF","OAuth2","3GPP","SBA","CVE-2026-8812",{"type":21,"children":22,"toc":242},"root",[23,31,74,81,109,115,128,137,150,156,217,223],{"type":24,"tag":25,"props":26,"children":28},"element","h1",{"id":27},"critical-advisory-http2-nrf-authorization-flaws-in-5g-standalone-deployments",[29],{"type":30,"value":8},"text",{"type":24,"tag":32,"props":33,"children":34},"p",{},[35,41,43,47,52,54,57,62,64,67,72],{"type":24,"tag":36,"props":37,"children":38},"strong",{},[39],{"type":30,"value":40},"Publication Date:",{"type":30,"value":42}," September 18, 2026",{"type":24,"tag":44,"props":45,"children":46},"br",{},[],{"type":24,"tag":36,"props":48,"children":49},{},[50],{"type":30,"value":51},"Author:",{"type":30,"value":53}," TelcoSec Threat Research Team",{"type":24,"tag":44,"props":55,"children":56},{},[],{"type":24,"tag":36,"props":58,"children":59},{},[60],{"type":30,"value":61},"Advisory ID:",{"type":30,"value":63}," TS-ADV-2026-004",{"type":24,"tag":44,"props":65,"children":66},{},[],{"type":24,"tag":36,"props":68,"children":69},{},[70],{"type":30,"value":71},"Impacted Protocols:",{"type":30,"value":73}," 3GPP TS 29.510 \u002F TS 33.501 (5G Service Based Architecture)",{"type":24,"tag":75,"props":76,"children":78},"h2",{"id":77},"executive-summary",[79],{"type":30,"value":80},"Executive Summary",{"type":24,"tag":32,"props":82,"children":83},{},[84,86,91,93,98,100,107],{"type":30,"value":85},"Security researchers at the ",{"type":24,"tag":36,"props":87,"children":88},{},[89],{"type":30,"value":90},"TelcoSec Research Group",{"type":30,"value":92}," have identified a critical authorization bypass pattern affecting early Release 16\u002F17 5G Standalone (SA) Core deployments. When Network Functions (NFs) register with the central ",{"type":24,"tag":36,"props":94,"children":95},{},[96],{"type":30,"value":97},"Network Repository Function (NRF)",{"type":30,"value":99}," via the ",{"type":24,"tag":101,"props":102,"children":104},"code",{"className":103},[],[105],{"type":30,"value":106},"nnrf-nfm",{"type":30,"value":108}," service, improper validation of OAuth2 JSON Web Tokens (JWT) allows rogue network elements to advertise themselves as authoritative AMFs or SMFs.",{"type":24,"tag":75,"props":110,"children":112},{"id":111},"technical-analysis",[113],{"type":30,"value":114},"Technical Analysis",{"type":24,"tag":32,"props":116,"children":117},{},[118,120,126],{"type":30,"value":119},"Under 3GPP specification TS 33.501, every NF discovery request across the Service-Based Interface (SBI) must be authorized by an access token issued by the NRF containing audience claims (",{"type":24,"tag":101,"props":121,"children":123},{"className":122},[],[124],{"type":30,"value":125},"aud",{"type":30,"value":127},") specifying the target NF type and NF instance ID.",{"type":24,"tag":129,"props":130,"children":132},"pre",{"code":131},"+----------------+      1. Discovery Request (No Token)       +----------------+\n|  Rogue 5G NF   | -----------------------------------------> |  5G NRF Node   |\n| (TelcoChisel)  | \u003C----------------------------------------- | (SBI Gateway)  |\n|                |      2. 200 OK with All Core Profiles      |                |\n+----------------+                                            +----------------+\n",[133],{"type":24,"tag":101,"props":134,"children":135},{"__ignoreMap":7},[136],{"type":30,"value":131},{"type":24,"tag":32,"props":138,"children":139},{},[140,142,148],{"type":30,"value":141},"When an operator misconfigures the NRF ",{"type":24,"tag":101,"props":143,"children":145},{"className":144},[],[146],{"type":30,"value":147},"service-authorization.strict-mode: false",{"type":30,"value":149}," fallback flag, the NRF accepts unsigned discovery queries, disclosing the full internal IP topology and cryptographic certificates of all active UDM, AUSF, and UPF instances.",{"type":24,"tag":75,"props":151,"children":153},{"id":152},"mitigation-remediation-guidelines",[154],{"type":30,"value":155},"Mitigation & Remediation Guidelines",{"type":24,"tag":157,"props":158,"children":159},"ol",{},[160,171,196],{"type":24,"tag":161,"props":162,"children":163},"li",{},[164,169],{"type":24,"tag":36,"props":165,"children":166},{},[167],{"type":30,"value":168},"Enforce Mutual TLS (mTLS)",{"type":30,"value":170},": Mandate strict bidirectional X.509 certificate validation across all N32 and SBI interfaces.",{"type":24,"tag":161,"props":172,"children":173},{},[174,179,181,186,188,194],{"type":24,"tag":36,"props":175,"children":176},{},[177],{"type":30,"value":178},"Strict Audience Checking",{"type":30,"value":180},": Validate ",{"type":24,"tag":101,"props":182,"children":184},{"className":183},[],[185],{"type":30,"value":125},{"type":30,"value":187}," and ",{"type":24,"tag":101,"props":189,"children":191},{"className":190},[],[192],{"type":30,"value":193},"scope",{"type":30,"value":195}," claims in every received JWT token at the target Service Producer.",{"type":24,"tag":161,"props":197,"children":198},{},[199,204,206],{"type":24,"tag":36,"props":200,"children":201},{},[202],{"type":30,"value":203},"Audit with TelcoChisel",{"type":30,"value":205},":\n",{"type":24,"tag":129,"props":207,"children":212},{"code":208,"language":209,"meta":7,"className":210},"# Run automated SBA OAuth2 token validation audit\ntelcochisel-5g-audit --nrf http:\u002F\u002F10.0.0.1:7777 --check-auth-bypass\n","bash",[211],"language-bash",[213],{"type":24,"tag":101,"props":214,"children":215},{"__ignoreMap":7},[216],{"type":30,"value":208},{"type":24,"tag":75,"props":218,"children":220},{"id":219},"hands-on-simulation",[221],{"type":30,"value":222},"Hands-on Simulation",{"type":24,"tag":32,"props":224,"children":225},{},[226,228,240],{"type":30,"value":227},"Operators and penetration testers can simulate this attack and test mitigation patches in the ",{"type":24,"tag":36,"props":229,"children":230},{},[231],{"type":24,"tag":232,"props":233,"children":237},"a",{"href":234,"rel":235},"https:\u002F\u002Fapp.telcosec.net",[236],"nofollow",[238],{"type":30,"value":239},"TelcoSec Academy 5G SBA Red Team Lab",{"type":30,"value":241},".",{"title":7,"searchDepth":243,"depth":243,"links":244},2,[245,246,247,248],{"id":77,"depth":243,"text":80},{"id":111,"depth":243,"text":114},{"id":152,"depth":243,"text":155},{"id":219,"depth":243,"text":222},"markdown","content:news:cve-2026-3gpp-sba-auth-bypass.md","content","news\u002Fcve-2026-3gpp-sba-auth-bypass.md","news\u002Fcve-2026-3gpp-sba-auth-bypass","md",{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"date":10,"author":11,"category":12,"tags":256,"body":257,"_type":249,"_id":250,"_source":251,"_file":252,"_stem":253,"_extension":254},[14,15,16,17,18,19],{"type":21,"children":258,"toc":418},[259,263,295,299,319,323,333,340,350,354,401,405],{"type":24,"tag":25,"props":260,"children":261},{"id":27},[262],{"type":30,"value":8},{"type":24,"tag":32,"props":264,"children":265},{},[266,270,271,274,278,279,282,286,287,290,294],{"type":24,"tag":36,"props":267,"children":268},{},[269],{"type":30,"value":40},{"type":30,"value":42},{"type":24,"tag":44,"props":272,"children":273},{},[],{"type":24,"tag":36,"props":275,"children":276},{},[277],{"type":30,"value":51},{"type":30,"value":53},{"type":24,"tag":44,"props":280,"children":281},{},[],{"type":24,"tag":36,"props":283,"children":284},{},[285],{"type":30,"value":61},{"type":30,"value":63},{"type":24,"tag":44,"props":288,"children":289},{},[],{"type":24,"tag":36,"props":291,"children":292},{},[293],{"type":30,"value":71},{"type":30,"value":73},{"type":24,"tag":75,"props":296,"children":297},{"id":77},[298],{"type":30,"value":80},{"type":24,"tag":32,"props":300,"children":301},{},[302,303,307,308,312,313,318],{"type":30,"value":85},{"type":24,"tag":36,"props":304,"children":305},{},[306],{"type":30,"value":90},{"type":30,"value":92},{"type":24,"tag":36,"props":309,"children":310},{},[311],{"type":30,"value":97},{"type":30,"value":99},{"type":24,"tag":101,"props":314,"children":316},{"className":315},[],[317],{"type":30,"value":106},{"type":30,"value":108},{"type":24,"tag":75,"props":320,"children":321},{"id":111},[322],{"type":30,"value":114},{"type":24,"tag":32,"props":324,"children":325},{},[326,327,332],{"type":30,"value":119},{"type":24,"tag":101,"props":328,"children":330},{"className":329},[],[331],{"type":30,"value":125},{"type":30,"value":127},{"type":24,"tag":129,"props":334,"children":335},{"code":131},[336],{"type":24,"tag":101,"props":337,"children":338},{"__ignoreMap":7},[339],{"type":30,"value":131},{"type":24,"tag":32,"props":341,"children":342},{},[343,344,349],{"type":30,"value":141},{"type":24,"tag":101,"props":345,"children":347},{"className":346},[],[348],{"type":30,"value":147},{"type":30,"value":149},{"type":24,"tag":75,"props":351,"children":352},{"id":152},[353],{"type":30,"value":155},{"type":24,"tag":157,"props":355,"children":356},{},[357,365,385],{"type":24,"tag":161,"props":358,"children":359},{},[360,364],{"type":24,"tag":36,"props":361,"children":362},{},[363],{"type":30,"value":168},{"type":30,"value":170},{"type":24,"tag":161,"props":366,"children":367},{},[368,372,373,378,379,384],{"type":24,"tag":36,"props":369,"children":370},{},[371],{"type":30,"value":178},{"type":30,"value":180},{"type":24,"tag":101,"props":374,"children":376},{"className":375},[],[377],{"type":30,"value":125},{"type":30,"value":187},{"type":24,"tag":101,"props":380,"children":382},{"className":381},[],[383],{"type":30,"value":193},{"type":30,"value":195},{"type":24,"tag":161,"props":386,"children":387},{},[388,392,393],{"type":24,"tag":36,"props":389,"children":390},{},[391],{"type":30,"value":203},{"type":30,"value":205},{"type":24,"tag":129,"props":394,"children":396},{"code":208,"language":209,"meta":7,"className":395},[211],[397],{"type":24,"tag":101,"props":398,"children":399},{"__ignoreMap":7},[400],{"type":30,"value":208},{"type":24,"tag":75,"props":402,"children":403},{"id":219},[404],{"type":30,"value":222},{"type":24,"tag":32,"props":406,"children":407},{},[408,409,417],{"type":30,"value":227},{"type":24,"tag":36,"props":410,"children":411},{},[412],{"type":24,"tag":232,"props":413,"children":415},{"href":234,"rel":414},[236],[416],{"type":30,"value":239},{"type":30,"value":241},{"title":7,"searchDepth":243,"depth":243,"links":419},[420,421,422,423],{"id":77,"depth":243,"text":80},{"id":111,"depth":243,"text":114},{"id":152,"depth":243,"text":155},{"id":219,"depth":243,"text":222},1790363495411]