Launch Week Day 1: Announcing Security Design Review
HIGH 7.2 Go

Ella Core has Privilege Escalation via Database Restore by NetworkManager role

GHSA-87j9-m7x6-hvw2 · CVE-2026-33906 · GO-2026-4873

Published · Modified

Description

Summary

The NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents.

Impact

A NetworkManager could replace the production database with a tampered copy to escalate to Admin, gaining access to user management, audit logs, debug endpoints, and operator identity configuration that the role was explicitly denied.

Fix

Backup and restore permissions have been removed from the NetworkManager role.

Ready to move

Start Securing

Free, no credit card | First findings in minutes