Description
A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.
Published: 2026-08-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

a flaw in the SecurityModeComplete Handler allows an attacker to manipulate the integrity check value, bypassing the component’s validation of incoming data. This improper validation can enable the attacker to perform unauthorized actions, potentially compromising system confidentiality, integrity, or availability. The weakness is captured by CWE‑345 (Information Disclosure) and CWE‑354 (Improper Validation).

Affected Systems

All installations of Linux Foundation Magma version 1.9.0 that have not applied the vendor’s fix are vulnerable. The component is part of the core Magma control plane and is used by operators building mobile network functions.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating a moderate to high severity. The EPSS score is not available, but the exploit is publicly documented and may be used. It is not listed in CISA’s KEV catalog, although the presence of a public exploit raises concern. Attackers can launch the exploit remotely, and the risk of exploitation is therefore non‑negligible.

Generated by OpenCVE AI on August 30, 2026 at 16:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Linux Foundation Magma to a version that contains the corrected integrity check in the SecurityModeComplete Handler
  • If an upgrade is not possible, restrict network exposure to the Magma control plane by implementing segmentation or firewall rules that limit remote access to the affected services
  • Enable detailed logging and real‑time monitoring for abnormal SecurityModeComplete requests to detect potential exploitation attempts

Generated by OpenCVE AI on August 30, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Linuxfoundation
Linuxfoundation magma
Vendors & Products Linuxfoundation
Linuxfoundation magma

Sun, 30 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.
Title Linux Foundation Magma SecurityModeComplete integrity check
First Time appeared Linux Foundation
Linux Foundation magma
Weaknesses CWE-345
CWE-354
CPEs cpe:2.3:o:linux_foundation:magma:*:*:*:*:*:*:*:*
Vendors & Products Linux Foundation
Linux Foundation magma
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Linux Foundation Magma
Linuxfoundation Magma
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-30T15:30:09.964Z

Reserved: 2026-08-29T18:44:02.751Z

Link: CVE-2026-82549

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T16:16:43.667

Modified: 2026-08-30T16:16:43.667

Link: CVE-2026-82549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T17:00:07Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-354

    Improper Validation of Integrity Check Value