CVE-2026-33906 details a privilege escalation vulnerability in Ella Core, a 5G core for private networks, affecting versions prior to 1.7.0. A NetworkManager role, which previously held backup and restore permissions, could exploit this by restoring a tampered SQLite database to escalate privileges to Admin, gaining unauthorized access to critical functions like user management and audit logs. Rated 7.2 HIGH on CVSS, this vulnerability has a network attack vector and low attack complexity, allowing a high-privileged attacker to achieve full confidentiality, integrity, and availability impact. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.0CPE matchmatch criteria | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.