CVE-2026-33906
7.2Ella · Core
Ella Core versions prior to 1.7.0 contain an improper privilege management vulnerability allowing a NetworkManager to escalate privileges to Admin via the database restore endpoint.
Executive summary
A critical privilege escalation vulnerability in Ella Core allows authenticated users with the NetworkManager role to achieve full administrative control over the 5G core network.
Vulnerability
The flaw resides in the restore endpoint, which failed to validate the contents of uploaded SQLite files. An attacker with the NetworkManager role can replace the production database with a malicious copy to gain unauthorized access to administrative functions, user management, and sensitive operator configurations.
Business impact
The exploitation of this vulnerability poses a severe risk to the integrity and confidentiality of private 5G network operations. By gaining administrative access, an attacker could manipulate audit logs, compromise user data, or disrupt network services, leading to significant operational downtime and potential regulatory non-compliance. Given the CVSS score of 7.2, this represents a high-severity risk that requires immediate attention to prevent unauthorized control over critical infrastructure.
Remediation
Immediate Action: Upgrade Ella Core to version 1.7.0 or higher, which removes the backup and restore permissions from the NetworkManager role to prevent misuse.
Proactive Monitoring: Audit logs should be reviewed for anomalous database restore activity or unexpected changes to administrative user accounts.
Compensating Controls: Implement strict access control lists on the management interface to ensure only authorized personnel can access the restore endpoint until the update is applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The potential for total administrative compromise makes this vulnerability a priority for remediation. Organizations utilizing Ella Core in private 5G environments must verify their current version and schedule an immediate update to version 1.7.0 to eliminate the privilege management flaw and secure the core infrastructure.