Junglewise Threat Intelligence

CVE-2026-44475: Ella Networks Ella Core security bypass in NGAP PathSwitchRequest

CVE-2026-44475 · Severity: medium · CVSS 6.1 · Published 2026-05-27

Technologies: github.com/ellanetworks/core (Go), Ella Networks Ella Core. Vendors: Ella Networks, Go.

Executive brief

Ella Core is a 5G core network platform used for private cellular networks. A vulnerability in how the system handles handovers between base stations allows a malicious base station to overwrite the security settings of a user's device. This could lead to the corruption of security profiles, potentially impacting the integrity of communications for specific users on the network.

Technical details

Ella Core (prior to version 1.10.0) contains a security check bypass (CWE-358) in its handling of NGAP PathSwitchRequest messages. The component fails to validate the UE Security Capabilities provided in the request against the values locally stored in the core network. An attacker controlling a malicious base station (gNB) can send a crafted PathSwitchRequest to overwrite the stored security capabilities of a target User Equipment (UE) with arbitrary values. This vulnerability is exploitable from an adjacent network (the radio access network) without authentication. The issue is resolved in version 1.10.0, which implements proper verification and logging of mismatches.

Affected products

  • Ella Networks core < 1.10.0

Timeline

  • 2026-05-06: disclosed: Initial disclosure by researcher
  • 2026-05-11: advisory: GitHub Advisory published
  • 2026-05-27: other: NVD publication

References

Related threats