Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-87j9-m7x6-hvw2 | Ella Core has Privilege Escalation via Database Restore by NetworkManager role |
Mon, 20 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks ella Core
|
|
| CPEs | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ellanetworks ella Core
|
Tue, 31 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks
Ellanetworks core |
|
| Vendors & Products |
Ellanetworks
Ellanetworks core |
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents. A NetworkManager could replace the production database with a tampered copy to escalate to Admin, gaining access to user management, audit logs, debug endpoints, and operator identity configuration that the role was explicitly denied. In version 1.7.0, backup and restore permissions have been removed from the NetworkManager role. | |
| Title | Ella Core has Privilege Escalation via Database Restore by NetworkManager role | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-31T18:53:56.905Z
Reserved: 2026-03-24T15:41:47.491Z
Link: CVE-2026-33906
Updated: 2026-03-31T18:51:15.479Z
Status : Analyzed
Published: 2026-03-27T21:17:26.800
Modified: 2026-04-20T12:33:13.623
Link: CVE-2026-33906
No data.
OpenCVE Enrichment
Updated: 2026-03-30T07:00:13Z
Github GHSA