PT-2026-26468 · Ella Core · Ella Core

P1-Aji

·

Published

2026-03-19

·

Updated

2026-03-27

·

CVE-2026-33282

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ella Core versions prior to 1.6.0
Description Ella Core, a 5G core designed for private networks, experiences a panic when processing a malformed NGAP LocationReport message. Specifically, the issue occurs with the ue-presence-in-area-of-interest event type when the optional UEPresenceInAreaOfInterestList IE is omitted. An attacker can exploit this by sending crafted NGAP messages to Ella Core, leading to a process crash and service disruption for all connected subscribers. No authentication is required for exploitation. The issue is related to the handling of NGAP messages and the absence of proper IE presence verification.
Recommendations Update to version 1.6.0 or later.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33282
GHSA-826Q-WRQ4-P23X
GO-2026-4780
SUSE-SU-2026:1135-1

Affected Products

Ella Core