CVE-2026-44473

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-connection, then creates a GTP tunnel towards that radio. This vulnerability is fixed in 1.10.0.
Configurations

No configuration.

History

27 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 17:16

Updated : 2026-05-27 20:03


NVD link : CVE-2026-44473

Mitre link : CVE-2026-44473

CVE.ORG link : CVE-2026-44473


JSON object : View

Products Affected

No product.

CWE
CWE-358

Improperly Implemented Security Check for Standard

CWE-863

Incorrect Authorization