A vulnerability has been found in Free5GC pcf up to 1.4.1. This affects the function HandleCreateSmPolicyRequest of the file internal/sbi/processor/smpolicy.go. The manipulation leads to null pointer dereference. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is df535f5524314620715e842baf9723efbeb481a7. Applying a patch is the recommended action to fix this issue.
References
| Link | Resource |
|---|---|
| https://github.com/free5gc/free5gc/issues/803 | Exploit Issue Tracking Third Party Advisory |
| https://github.com/free5gc/free5gc/issues/803#issue-3815770007 | Exploit Issue Tracking Third Party Advisory |
| https://github.com/free5gc/pcf/ | Product |
| https://github.com/free5gc/pcf/commit/df535f5524314620715e842baf9723efbeb481a7 | Patch |
| https://github.com/free5gc/pcf/pull/62 | Issue Tracking |
| https://vuldb.com/?ctiid.343638 | Permissions Required VDB Entry |
| https://vuldb.com/?id.343638 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.741194 | Third Party Advisory VDB Entry |
Configurations
History
11 Feb 2026, 19:35
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Free5gc pcf
Free5gc |
|
| References | () https://github.com/free5gc/free5gc/issues/803 - Exploit, Issue Tracking, Third Party Advisory | |
| References | () https://github.com/free5gc/free5gc/issues/803#issue-3815770007 - Exploit, Issue Tracking, Third Party Advisory | |
| References | () https://github.com/free5gc/pcf/ - Product | |
| References | () https://github.com/free5gc/pcf/commit/df535f5524314620715e842baf9723efbeb481a7 - Patch | |
| References | () https://github.com/free5gc/pcf/pull/62 - Issue Tracking | |
| References | () https://vuldb.com/?ctiid.343638 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.343638 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.741194 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:free5gc:pcf:*:*:*:*:*:*:*:* |
02 Feb 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-02 02:16
Updated : 2026-02-11 19:35
NVD link : CVE-2026-1739
Mitre link : CVE-2026-1739
CVE.ORG link : CVE-2026-1739
JSON object : View
Products Affected
free5gc
- pcf
