CVE-2026-44474
Received Received - Intake
BaseFortify

Publication date: 2026-05-27

Last updated on: 2026-05-27

Assigner: GitHub, Inc.

Description
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 Β§6.9.5.1 β€” it could send a NAS Security Mode Command while an N2 handover was still pending (and vice versa). Concurrent Security Mode Command and N2 handover produce a KgNB mismatch between the UE and target gNB, causing the handover to fail. Requires a stalled gNB + re-registration race to trigger. This vulnerability is fixed in 1.10.0.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-27
Last Modified
2026-05-27
Generated
2026-05-28
AI Q&A
2026-05-27
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
ella_networks ella_core to 1.10.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-358 The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The vulnerability exists in Ella Core, a 5G core designed for private networks, prior to version 1.10.0. It fails to enforce security rules on concurrent running of security procedures as defined in TS 33.501 Β§6.9.5.1. Specifically, it can send a NAS Security Mode Command while an N2 handover is still pending, or vice versa. This concurrency causes a KgNB mismatch between the User Equipment (UE) and the target gNB, which leads to handover failure.

Triggering this vulnerability requires a stalled gNB and a re-registration race condition.

The issue was fixed in version 1.10.0 of Ella Core.


How can this vulnerability impact me? :

This vulnerability can cause handover failures in 5G private networks using Ella Core prior to version 1.10.0. The KgNB mismatch between the UE and target gNB disrupts the handover process, potentially leading to degraded network performance or dropped connections during mobility events.

The CVSS base score of 3.7 indicates a low severity impact, with limited integrity and availability impact but no confidentiality impact.


What immediate steps should I take to mitigate this vulnerability?

The vulnerability is fixed in Ella Core version 1.10.0. Immediate mitigation involves upgrading to version 1.10.0 or later to ensure enforcement of security rules on concurrent running of security procedures.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The provided information does not specify any direct impact of this vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart