Description
A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper input validation flaw in the NGSetupRequest Handler of Linux Foundation Magma, specifically affecting the NG-IoT-DefaultPagingDRX argument. The flaw allows an attacker to supply crafted input that bypasses the ordinary validation logic, potentially leading to arbitrary code execution or other forms of remote compromise as it does not enforce correct data formats or bounds. This weakness is classified as CWE-20, which denotes improper input validation.

Affected Systems

Linux Foundation Magma version 1.9.0 is affected. No other product versions are listed as vulnerable in the current data.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, and the exploit is reported as publicly available, meaning the likelihood of exploitation is significant. The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, but the presence of a public exploit indicates that attackers can target the system remotely with relatively low effort. The failure to apply proper input validation opens the path for code execution or other malicious actions depending on the attacker’s execution capabilities. The overall risk level can be considered high for exposed Magma instances until a patch or mitigative measure is applied.

Generated by OpenCVE AI on August 30, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to a later version of Magma that resolves the NGSetupRequest input validation bug.
  • Configure network controls (e.g., firewalls, reverse proxies) to limit access to the Magma service only to trusted internal or cloud hosts.
  • Enable comprehensive logging of NGSetupRequest traffic and actively monitor for anomalous or malformed values of NG-IoT-DefaultPagingDRX to detect potential exploitation attempts.

Generated by OpenCVE AI on August 30, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title Linux Foundation Magma NGSetupRequest input validation
First Time appeared Linux Foundation
Linux Foundation magma
Weaknesses CWE-20
CPEs cpe:2.3:o:linux_foundation:magma:*:*:*:*:*:*:*:*
Vendors & Products Linux Foundation
Linux Foundation magma
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Linux Foundation Magma
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-30T15:45:09.408Z

Reserved: 2026-08-29T18:44:07.704Z

Link: CVE-2026-82550

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T16:16:43.847

Modified: 2026-08-30T16:16:43.847

Link: CVE-2026-82550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T17:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation