Description
A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-08-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the InitialUEMessage handler of Linux Foundation Magma version 1.9.0 that allows remote attackers to read sensitive internal data. The flaw stems from an unknown function that mishandles incoming messages and can reveal confidential information, mapping to CWE-200 and CWE-284. Because the disclosure can occur without authenticated access, it poses a confidentiality risk to users relying on Magma for network control.

Affected Systems

The affected product is Linux Foundation Magma, specifically version 1.9.0. No other versions are explicitly listed as vulnerable in the data, so the impact is confined to installations running that release.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity; the EPSS score is unavailable, but the vulnerability is publicly disclosed, meaning the exploit appears on open source channels. Attackers can initiate the exploit remotely, likely via the control plane interface. Although the vulnerability is not yet listed in CISA KeV, the remote origin and lack of authentication control elevate the operational risk for exposed environments.

Generated by OpenCVE AI on August 30, 2026 at 16:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for Linux Foundation Magma;
  • Limit external access to the Magma control plane interfaces;
  • Monitor logs for abnormal InitialUEMessage activity;

Generated by OpenCVE AI on August 30, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Linuxfoundation
Linuxfoundation magma
Vendors & Products Linuxfoundation
Linuxfoundation magma

Sun, 30 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Title Linux Foundation Magma InitialUEMessage information disclosure
First Time appeared Linux Foundation
Linux Foundation magma
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:o:linux_foundation:magma:*:*:*:*:*:*:*:*
Vendors & Products Linux Foundation
Linux Foundation magma
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Linux Foundation Magma
Linuxfoundation Magma
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-30T15:00:10.066Z

Reserved: 2026-08-29T18:43:58.210Z

Link: CVE-2026-82548

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T15:16:44.417

Modified: 2026-08-30T15:16:44.417

Link: CVE-2026-82548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T17:00:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control