CVE-2025-66719 | Free5GC 1.4.0 access_token.go AccessTokenScopeCheck targetNF access control (Issue 736)
A vulnerability categorized as critical has been discovered in Free5GC 1.4.0. Affected is the function AccessTokenScopeCheck of the file internal/sbi/processor/access_token.go. Executing a manipulation of the argument targetNF can lead to improper access controls.
This vulnerability is handled as CVE-2025-66719. The attack can be executed remotely. There is not any exploit available.
Applying a patch is advised to resolve this issue.