5G Core Security Flaw in Ella Core by Ella Networks
CVE-2026-44475
6.1MEDIUM
What is CVE-2026-44475?
Ella Core, developed for 5G private networks, contains a significant security weakness in its handling of UE Security Capabilities within NGAP PathSwitchRequest messages. Prior to version 1.10.0, the system fails to adequately validate these capabilities against stored data, allowing a malicious gNB to overwrite the UE security information with arbitrary values. This could potentially lead to unauthorized access or manipulation of network resources. Users are advised to update to version 1.10.0 to mitigate this risk.
Affected Version(s)
core < 1.10.0
