PT-2026-26469 · Ella Core · Ella Core

·

CVE-2026-33283

·

Published

2026-03-19

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ella Core versions prior to 1.6.0
Description Ella Core, a 5G core designed for private networks, experiences a panic when processing improperly formatted UL NAS Transport NAS messages that lack a Request Type. An attacker can exploit this by sending specially crafted NAS messages to Ella Core, leading to a process crash and service disruption for all connected subscribers. This does not require authentication. The issue occurs when receiving an UL NAS Message without a Request Type and no SM Context.
Recommendations Update to version 1.6.0 or later.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33283
GHSA-3366-GW57-FCM5
GO-2026-4776
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Affected Products

Ella Core