PT-2026-28564 · Ella Core · Ella Core

CVE-2026-33906

·

Publicado

2026-03-26

·

Atualizado

2026-07-30

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ella Core versions prior to 1.7.0
Description Ella Core is a 5G core designed for private networks. The NetworkManager role had backup and restore permissions. The restore endpoint accepted any valid SQLite file without content verification. This allowed a NetworkManager to replace the production database with a modified copy, escalating privileges to Admin. This granted access to user management, audit logs, debug endpoints, and operator identity configuration, which the role was explicitly denied. The affected endpoint is /restore. The vulnerable parameter is the SQLite file provided to the /restore endpoint.
Recommendations Update to version 1.7.0 or later.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33906
GHSA-87J9-M7X6-HVW2
GO-2026-4873
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1205-1

Produtos afetados

Ella Core