5G Core Security Flaw in Ella Core by Ella Networks
CVE-2026-44475

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-44475?

Ella Core, developed for 5G private networks, contains a significant security weakness in its handling of UE Security Capabilities within NGAP PathSwitchRequest messages. Prior to version 1.10.0, the system fails to adequately validate these capabilities against stored data, allowing a malicious gNB to overwrite the UE security information with arbitrary values. This could potentially lead to unauthorized access or manipulation of network resources. Users are advised to update to version 1.10.0 to mitigate this risk.

Affected Version(s)

core < 1.10.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.