Sceawere

Vulnerability Detail

CVE-2026-82547UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Magma Improper Authentication Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Linux Foundation
Product
Magma
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The manipulation results in improper authentication. The attack can be launched remotely. The exploit has been made public and could be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-30T15:16:44.237Z",
  "pubdate": "2026-08-30T15:16:44.237Z",
  "executiveSummary": "A critical improper authentication vulnerability exists in Linux Foundation Magma version 1.9.0, specifically within the Registration Complete Message Handler. This flaw allows remote, unauthenticated attackers to bypass security controls during the device registration process.\nThe vulnerability resides in the state machine logic handled by tasks/amf/amf_fsm.cpp, enabling an adversary to manipulate the authentication flow. Successful exploitation leads to unauthorized access to network resources or services by masquerading as a legitimate user or device.\nGiven that the exploit is publicly available, the risk to operational environments is high. The vulnerability can be triggered remotely, requiring no prior authentication, which significantly lowers the barrier for exploitation. Affected systems are exposed to unauthorized network participation, potentially leading to identity spoofing, service disruption, or unauthorized access to sensitive core network communication protocols.",
  "technicalDetails": "The vulnerability is situated within the Access and Mobility Management Function (AMF) of the Magma 1.9.0 release. Specifically, the flaw exists within the 'Registration Complete Message Handler' logic implemented in the file 'tasks/amf/amf_fsm.cpp'.\nThe root cause of this vulnerability lies in an improper implementation of the finite state machine (FSM) that governs the registration sequence for User Equipment (UE). In the 5G/LTE signaling flow, the Registration Complete message is intended to be the final confirmation of a secure authentication handshake. However, the logic in 'amf_fsm.cpp' fails to properly validate the integrity or the context of the registration session when this message is received.\nThe exploitation flow proceeds as follows: An attacker sends a crafted 'Registration Complete' message to the AMF component. Because the state machine does not strictly verify that the preceding Authentication Request/Response exchange was completed successfully, or because it improperly trusts the incoming message parameters, the FSM transitions to an 'Authenticated' or 'Registered' state prematurely.\nBy bypassing the standard authentication challenge-response mechanism, an attacker can effectively inject themselves into the network's subscriber registry. This remote manipulation allows the attacker to associate a malicious device with a valid (or spoofed) identity within the core network. Since the Registration Complete message is processed without requiring prior valid authentication, the attacker circumvents the security barriers meant to prevent unauthorized network access.\nThe impact is significant: once the AMF state is erroneously set to registered, the attacker can potentially send and receive traffic, perform signaling operations, or intercept communication intended for legitimate subscribers. This lack of authentication verification represents a complete failure of the identity establishment protocol at the AMF layer. Because the exploit is public, the attack vector is well-documented, allowing for automated exploitation of vulnerable 5G core network deployments that utilize Magma version 1.9.0."
}
CVE-2026-82547: Magma Improper Authentication Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere