GHSA-87j9-m7x6-hvw2

Suggest an improvement
Source
https://github.com/advisories/GHSA-87j9-m7x6-hvw2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-87j9-m7x6-hvw2/GHSA-87j9-m7x6-hvw2.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-87j9-m7x6-hvw2
Aliases
Published
2026-03-26T22:14:54Z
Modified
2026-04-02T20:56:29Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Ella Core has Privilege Escalation via Database Restore by NetworkManager role
Details

Summary

The NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents.

Impact

A NetworkManager could replace the production database with a tampered copy to escalate to Admin, gaining access to user management, audit logs, debug endpoints, and operator identity configuration that the role was explicitly denied.

Fix

Backup and restore permissions have been removed from the NetworkManager role.

Database specific
{
    "cwe_ids":  [
        "CWE-269"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-26T22:14:54Z",
    "nvd_published_at":  "2026-03-27T21:17:26Z",
    "severity":  "HIGH"
}
References

Affected packages

Go / github.com/ellanetworks/core

Package

Name
github.com/ellanetworks/core
View open source insights on deps.dev
Purl
pkg:golang/github.com/ellanetworks/core

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-87j9-m7x6-hvw2/GHSA-87j9-m7x6-hvw2.json"