Backup and Restore Permission Issue in Ella Core 5G Solution by Ella Networks
CVE-2026-33906

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33906?

Ella Core, designed for private 5G networks, had a significant security flaw where the NetworkManager role was improperly allowed backup and restore permissions prior to version 1.7.0. This vulnerability enabled a malicious NetworkManager to exploit the restore endpoint, which accepted any valid SQLite file without appropriate content verification. Consequently, an attacker could replace the legitimate production database with a manipulated version, leading to unauthorized access to critical components such as user management, audit logs, debug endpoints, and operator identity configurations that should not have been accessible. The issue has been addressed in version 1.7.0 by removing these permissions from the NetworkManager role, enhancing the overall security posture of the product.

Affected Version(s)

core < 1.7.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.