{"id":"CVE-2026-44475","aliases":["GHSA-pwfh-mqp3-pqwj","GO-2026-5554"],"url":"https://o3.security/vulnerability/CVE-2026-44475","summary":"Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest","details":"## Summary\n\nElla Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values. A malicious gNB can overwrite Ella Core's stored UE security capabilities for any UE with arbitrary values by sending a single crafted PathSwitchRequest.\n\n## Impact\n\nA gNB can corrupt Ella Core's stored UE security capabilities for a target UE.\n\n## Fix\n\nThe PathSwitchRequest handler now compares the received UE Security Capabilities against Ella Core's locally stored values, preserves the stored values on mismatch, returns them in the PathSwitchRequestAcknowledge, and logs the event.","published":"2026-05-27T15:15:27.767Z","modified":"2026-08-12T03:51:26.493619968Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L"},"epss":{"score":0.00148,"percentile":0.04225,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/ellanetworks/core","fixedVersion":"1.10.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44475.json"},{"type":"ADVISORY","url":"https://github.com/ellanetworks/core/security/advisories/GHSA-pwfh-mqp3-pqwj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44475"},{"type":"PACKAGE","url":"https://github.com/ellanetworks/core"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.493619968Z"}}