Junglewise Threat Intelligence

CVE-2026-24079: Qualcomm cryptographic issue in registration request processing

CVE-2026-24079 · Severity: high · CVSS 8.1 · Published 2026-08-04

Vendors: Qualcomm.

Executive brief

Qualcomm components contain a cryptographic weakness when processing registration requests with malformed or missing authentication parameters. An attacker could exploit this flaw to bypass authentication controls or compromise the security of registration workflows, potentially leading to unauthorized access or system compromise.

Technical details

A cryptographic issue exists in the registration request processing logic when handling malformed or missing authentication parameters. The vulnerability affects authentication validation, allowing an attacker to send specially crafted registration requests that bypass security controls. The attack requires network access to the affected registration endpoint. Successful exploitation could result in authentication bypass or cryptographic downgrade. Patches are available from Qualcomm as of August 2026.

Affected products

  • Qualcomm <UNKNOWN>

Timeline

  • 2026-08-04: disclosed
  • 2026-08-04: patched

References