CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-8233: Session Hijacking Vulnerability in Dotouch XproUPF

July 31, 2026

CVE-2026-8233 is a session hijacking vulnerability discovered in Dotouch's XproUPF, a 5G core network User Plane Function. The flaw allows an attacker to inject a PFCP Session Modification Request, causing the UPF to forward a victim's uplink traffic to the attacker. It has a CVSS score of 4.6 and has been addressed by the vendor.