CVE-2026-82550 MEDIUM

CVE-2026-82550: Linux Foundation Magma NGSetupRequest input validation

Vendor Linux Foundation
Product Magma
Weakness CWE-20 · Input validation
Published August 30, 2026
Last update August 30, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Key dates

02Disclosure timeline

August 30, 2026 CVE published

Related vulnerabilities

04Related CVE