Description
A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The manipulation results in improper authentication. The attack can be launched remotely. The exploit has been made public and could be used.
Published: 2026-08-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Registration Complete Message Handler within the AMF component of Linux Foundation Magma. An attacker can manipulate the message handling process, causing the system to accept authentication credentials that are not properly verified. The result is that an unauthenticated user gains the privileges granted to a legitimately authenticated session. The flaw is classified under CWE‑287 and would allow an attacker to impersonate legitimate entities or obtain unauthorized access to services managed by the AMF.

Affected Systems

The affected product is Linux Foundation Magma version 1.9.0. The flaw is located in the tasks/amf/amf_fsm.cpp component. Systems running this exact version without additional authentication safeguards are at risk. No other affected versions are mentioned, so any installations matching this configuration should be evaluated for exposure.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. While the EPSS score is not available, a publicly disclosed exploit that can be launched remotely indicates a tangible exploitation risk. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote because the description explicitly states that the attack can be launched remotely, and the exploit is public.

Generated by OpenCVE AI on August 30, 2026 at 16:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install any newer Magma releases that contain a fix for this authentication flaw.
  • If a patch is not available, isolate the AMF component from untrusted networks or enforce additional authentication at the network perimeter to reduce exposure to remote exploitation.
  • Review the AMF authentication mechanism and ensure that proper credential validation is enforced before processing registration complete messages.

Generated by OpenCVE AI on August 30, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Linuxfoundation
Linuxfoundation magma
Vendors & Products Linuxfoundation
Linuxfoundation magma

Sun, 30 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The manipulation results in improper authentication. The attack can be launched remotely. The exploit has been made public and could be used.
Title Linux Foundation Magma Registration Complete Message amf_fsm.cpp improper authentication
First Time appeared Linux Foundation
Linux Foundation magma
Weaknesses CWE-287
CPEs cpe:2.3:o:linux_foundation:magma:*:*:*:*:*:*:*:*
Vendors & Products Linux Foundation
Linux Foundation magma
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Linux Foundation Magma
Linuxfoundation Magma
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-30T14:45:08.222Z

Reserved: 2026-08-29T18:43:53.333Z

Link: CVE-2026-82547

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T15:16:44.237

Modified: 2026-08-30T15:16:44.237

Link: CVE-2026-82547

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T16:30:17Z

Weaknesses