Input Validation Flaw in Ella Core 5G Network Management
CVE-2026-34762
2.7LOW
What is CVE-2026-34762?
Ella Core, a 5G core designed for private networks, is susceptible to an input validation error in its API. Specifically, the PUT /api/v1/subscriber/{imsi} endpoint allows for an IMSI identifier to be provided both in the URL path and in the JSON body without verifying their consistency. This loophole enables an authenticated NetworkManager to alter the policies of any subscriber while the audit logs may display a misleading or unrelated IMSI. This vulnerability has been addressed in version 1.8.0 of Ella Core.
Affected Version(s)
core < 1.8.0
