Executive brief
Magma, an open-source mobile core network platform, improperly validates 5G setup handshakes between base stations and the Access Gateway. An attacker can send NGAP messages without completing the required NGSetup process, bypassing security checks and gaining unauthorized access to base station capabilities, user contexts, and the ability to register unauthorized devices on the network.
Technical details
The vulnerability is a state validation bypass in the NGSetup Handler component (ngap_amf_handlers.c) of Magma's Access Management Function (AMF). The NGSetup message should be the first NGAP message after establishing an SCTP channel, but the implementation fails to enforce this requirement. An attacker with network access to the AMF can send NGAP messages (e.g., InitialUEMessage) without completing NGSetup, bypassing gNB capability negotiation and security validation. This allows an attacker to spoof base station identities, inject arbitrary UE contexts, and register unauthorized devices. The vulnerability requires network access to the NGAP interface but no authentication. Patches or workarounds are not mentioned in the available advisory.
Affected products
- Linux Foundation Magma 1.9.0
Timeline
- 2026-07-15: disclosed: Issue reported on GitHub
- 2026-08-30: advisory: CVE-2026-82551 published