Skip to content
Applications

CVE-2026-24079

8.1
High
EPSS 0.13%Patch availableAug 5, 2026

Authentication bypass in registration handling via malformed or missing auth params.

common questions

Is CVE-2026-24079 being exploited?

Not confirmed. CVE-2026-24079 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.13% probability of exploitation in the next 30 days.

How severe is CVE-2026-24079?

CVE-2026-24079 is rated High with a CVSS score of 8.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.

Is there a patch for CVE-2026-24079?

Yes. A fix has been recorded for CVE-2026-24079. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.

What does CVE-2026-24079 affect?

CVE-2026-24079 affects Registration endpoints, Identity providers (IdP), Web applications, API backends processing auth params. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.

What should I do about CVE-2026-24079?

Harden parameter validation, block malformed requests, monitor logs, apply vendor patch when available.

Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.

executive summary
technical analysis
affected
Registration endpointsIdentity providers (IdP)Web applicationsAPI backends processing auth params
impact

Bypass auth during registration via malformed/missing parameters to create or takeover accounts and gain unauthorized access.

action required

Immediate action required

affected versions
Qualcomm, Inc. Snapdragon
  • affectedAR8035
  • affectedCSRA6620
  • affectedCSRA6640
  • affectedFastConnect 6200
  • affectedFastConnect 6700
  • affectedFastConnect 6800
  • affectedFastConnect 6900
  • affectedFastConnect 7800
  • affectedFSM200 Platform
  • affectedFSM20055
  • affectedFWA Gen 3 Ultra Platform
  • affectedG1 Gen 1
  • affectedMilos
  • affectedNetrani
  • affectedOrne
  • affectedPalawan25
  • affectedQCA6174A
  • affectedQCA6391
  • affectedQCA6574AU
  • affectedQCA6584AU
  • affectedQCA6595AU
  • affectedQCA6678AQ
  • affectedQCA6688AQ
  • affectedQCA6696
  • affectedQCA6698AQ
  • affectedQCA6698AU
  • affectedQCA6797AQ
  • affectedQCA8081
  • affectedQCA8337
  • affectedQCC710
  • affectedQCM2290
  • affectedQCM4325
  • affectedQCM4490
  • affectedQCM5430
  • affectedQCM6490
  • affectedQCN6024
  • affectedQCN6224
  • affectedQCN6274
  • affectedQCN9011
  • affectedQCN9012
  • affectedQCN9024
  • affectedQCS2290
  • affectedQCS4290
  • affectedQCS4490
  • affectedQCS8550
  • affectedQEP8111
  • affectedQFW7114
  • affectedQFW7124
  • affectedQMP1000
  • affectedQualcomm Video Collaboration VC3 Platform
  • affectedRobotics RB2 Platform
  • affectedSD 8 Gen1 5G
  • affectedSD662
  • affectedSDX61
  • affectedSM6225P
  • affectedSM6650P
  • affectedSM7325P
  • affectedSM7435
  • affectedSM7550
  • affectedSM7550P
  • affectedSM7635P
  • affectedSM7675
  • affectedSM7675P
  • affectedSM8475P
  • affectedSM8550P
  • affectedSM8635
  • affectedSM8635P
  • affectedSM8650Q
  • affectedSM8750P
  • affectedSnapdragon 4 Gen 1 Mobile Platform
  • affectedSnapdragon 4 Gen 2 Mobile Platform
  • affectedSnapdragon 460 Mobile Platform
  • affectedSnapdragon 480 5G Mobile Platform
  • affectedSnapdragon 480+ 5G Mobile Platform
  • affectedSnapdragon 6 Gen 1 Mobile Platform
  • affectedSnapdragon 6 Gen 3 Mobile Platform
  • affectedSnapdragon 6 Gen 4 Mobile Platform
  • affectedSnapdragon 662 Mobile Platform
  • affectedSnapdragon 680 4G Mobile Platform
  • affectedSnapdragon 685 4G Mobile Platform
  • affectedSnapdragon 690 5G Mobile Platform
  • affectedSnapdragon 695 5G Mobile Platform
  • affectedSnapdragon 7 Gen 1 Mobile Platform
  • affectedSnapdragon 7+ Gen 2 Mobile Platform
  • affectedSnapdragon 778G 5G Mobile Platform
  • affectedSnapdragon 778G+ 5G Mobile Platform
  • affectedSnapdragon 782G Mobile Platform
  • affectedSnapdragon 7c+ Gen 3 Compute
  • affectedSnapdragon 7s Gen 3 Mobile Platform
  • affectedSnapdragon 8 Elite
  • affectedSnapdragon 8 Gen 1 Mobile Platform
  • affectedSnapdragon 8 Gen 2 Mobile Platform
  • affectedSnapdragon 8 Gen 3 Mobile Platform
  • affectedSnapdragon 8+ Gen 1 Mobile Platform
  • affectedSnapdragon 8+ Gen 2 Mobile Platform
  • affectedSnapdragon 865 5G Mobile Platform
  • affectedSnapdragon 865+ 5G Mobile Platform
  • affectedSnapdragon 870 5G Mobile Platform
  • affectedSnapdragon 888 5G Mobile Platform
  • affectedSnapdragon 888+ 5G Mobile Platform
  • affectedSnapdragon Auto 5G Modem-RF
  • affectedSnapdragon Auto 5G Modem-RF Gen 2
  • affectedSnapdragon W5+ Gen 1 Wearable Platform
  • affectedSnapdragon X32 5G Modem-RF System
  • affectedSnapdragon X35 5G Modem-RF System
  • affectedSnapdragon X53 5G Modem-RF System
  • affectedSnapdragon X55 5G Modem-RF System
  • affectedSnapdragon X65 5G Modem-RF System
  • affectedSnapdragon X72 5G Modem-RF System
  • affectedSnapdragon X75 5G Modem-RF System
  • affectedSW5100
  • affectedSW5100P
  • affectedSW6100
  • affectedSW6100P
  • affectedThemisto
  • affectedWCD9335
  • affectedWCD9340
  • affectedWCD9370
  • affectedWCD9371
  • affectedWCD9375
  • affectedWCD9378
  • affectedWCD9380
  • affectedWCD9385
  • affectedWCD9390
  • affectedWCD9395
  • affectedWCN3910
  • affectedWCN3950
  • affectedWCN3980
  • affectedWCN3988
  • affectedWCN6650
  • affectedWCN6755
  • affectedWCN7860
  • affectedWCN7861
  • affectedWCN7880
  • affectedWCN7881
  • affectedWSA8810
  • affectedWSA8815
  • affectedWSA8830
  • affectedWSA8832
  • affectedWSA8835
  • affectedWSA8840
  • affectedWSA8845
  • affectedWSA8845H

As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.

how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references
get alerted

Track only the vulnerabilities that affect your infrastructure.

start for free