CVE-2026-82548
Received Received - Intake

Information Disclosure in Linux Foundation Magma 1.9.0

Vulnerability report for CVE-2026-82548, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: VulDB

Description

A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_foundation magma 1.9.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-82548 is a vulnerability in Linux Foundation Magma 1.9.0 where the Access Gateway (AGW) component's AMF subcomponent incorrectly processes non-clear text Information Elements (IEs) in the InitialUEMessage during the 5G registration process. This violates 3GPP standards which require cleartext IEs when a device lacks a valid 5G NAS security context.

Detection Guidance

To detect CVE-2026-82548, monitor InitialUEMessage traffic in Magma v1.9.0 for non-clear text Information Elements (IEs) in the AMF subcomponent. Check for non-clear text Capability 5GMM IEs during 5G registration processes. Use network sniffing tools like Wireshark to analyze NAS signaling messages for compliance with 3GPP standards TS 24.501 and TS 33.501.

Impact Analysis

This vulnerability may allow attackers to extract sensitive device capability details from non-clear text IEs, enabling device fingerprinting or profiling. It could lead to information disclosure as unauthorized parties gain access to device-specific data during the 5G registration process.

Compliance Impact

This vulnerability may violate data protection requirements under GDPR and HIPAA by enabling unauthorized access to sensitive device information during network registration. Compliance could be impacted as it risks exposing personal or device-specific data without proper security controls.

Mitigation Strategies

Update Magma to a patched version where the AMF rejects non-clear text IEs in InitialUEMessage. If immediate patching is not possible, configure the AMF to enforce clear text IE validation per 3GPP standards. Isolate vulnerable Docker-based AGW configurations until fixed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82548. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart