Junglewise Threat Intelligence

CVE-2026-44474: Ella Networks Ella Core improper security check in 5G NAS procedures

CVE-2026-44474 · Severity: low · CVSS 3.7 · Published 2026-05-27

Technologies: github.com/ellanetworks/core (Go), Ella Networks Ella Core. Vendors: Ella Networks, Go.

Executive brief

Ella Core is a 5G core network platform used for private cellular networks. A flaw in how it handles security procedures can cause mobile devices to lose their connection during a handover between base stations. This results in a service outage for the affected user and requires a specific set of network conditions to occur.

Technical details

Ella Core does not properly enforce the 3GPP TS 33.501 §6.9.5.1 standard regarding concurrent security procedures. Specifically, the system may send a NAS Security Mode Command while an N2 handover is still pending, or vice versa. This concurrency creates a KgNB key mismatch between the User Equipment (UE) and the target gNB, causing the handover to fail. Exploitation requires a specific race condition involving a stalled gNB and a re-registration event. The issue is addressed in version 1.10.0 by blocking concurrent Security Mode Command and N2 handover procedures.

Affected products

  • Ella Networks core < 1.10.0

Timeline

  • 2026-05-06: disclosed: Initial disclosure to vendor
  • 2026-05-11: advisory: GitHub Advisory published
  • 2026-05-27: other: NVD published date

References

Related threats