Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mosaic5g:flexric:2.0.0:*:*:*:*:*:*:* |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass in FlexRIC v2.0.0 Enables Deletion of Other xApp Subscriptions | |
| First Time appeared |
Mosaic5g
Mosaic5g flexric |
|
| Vendors & Products |
Mosaic5g
Mosaic5g flexric |
Tue, 02 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass Allows xApp to Delete Other xApp Subscriptions in FlexRIC | |
| Weaknesses | CWE-284 |
Tue, 02 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-617 | |
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass Allows xApp to Delete Other xApp Subscriptions in FlexRIC | |
| Weaknesses | CWE-284 |
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in src/ric/iApp/xapp_ric_id.c compares m0->xapp_id against itself (m0->xapp_id) instead of the other argument (m1->xapp_id), effectively ignoring the xApp identity dimension. A malicious xApp connected to the iApp (port 36422) can delete any other xApp's subscriptions by sending an E42_RIC_SUBSCRIPTION_DELETE_REQUEST with a matching ric_gen_id. This breaks multi-tenant isolation in any deployment with multiple xApps sharing the same RIC. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-02T15:29:56.809Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37233
Updated: 2026-06-02T15:29:50.619Z
Status : Analyzed
Published: 2026-06-01T19:16:33.743
Modified: 2026-06-03T17:16:08.960
Link: CVE-2026-37233
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:55:16Z