CVE-2026-34761 describes a denial-of-service vulnerability in Ella Core, a 5G core solution for private networks, affecting versions prior to 1.8.0. An attacker with high privileges can cause a gNodeB to send a specific NGAP handover failure message, leading to a system panic and service disruption for all connected subscribers. This issue has a CVSSv3.1 score of 5.8 (Medium), reflecting a high impact on availability with high attack complexity and required privileges. There is currently no evidence of active exploitation, public exploit code, or significant community attention regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.0CPE matchmatch criteria | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.