A vulnerability has been identified in the system firmware of NVIDIA DGX Spark, tracked as CVE-2026-47626. The flaw allows a privileged attacker to trigger an out-of-bounds write condition within the firmware. Successful exploitation can result in a range of severe impacts including arbitrary code execution, escalation of privileges, denial of service, information disclosure, and data tampering. The vulnerability requires privileged access to exploit, somewhat limiting the attack surface. NVIDIA has published a security advisory via their product-security GitHub repository. The vulnerability is catalogued by both NVD (National Vulnerability Database) and the CVE Program. Given the potential for code execution and privilege escalation at the firmware level, the severity is considered high. Organizations using NVIDIA DGX Spark hardware should monitor for firmware patches and apply mitigations as soon as available.