← Terug naar overzicht

CVE-2026-24169 affects NVIDIA UFM Enterprise, specifically its plugin management API. An authenticated user with low privileges can exploit this vulnerability by sending a specially crafted API request to inject arbitrary code. Successful exploitation can result in remote code execution, privilege escalation, and information disclosure. The vulnerability highlights a critical risk in NVIDIA's network fabric management platform, which is commonly used in high-performance computing and data center environments. The low privilege requirement for exploitation increases the likelihood of abuse by insider threats or compromised accounts. NVIDIA has published a security advisory via their product-security GitHub repository. The vulnerability has been assigned a high criticality rating.

Affected products

  • NVIDIA UFM Enterprise

Related CVE's

  • CVE-2026-24169

Categories

  • Enterprise Applications
  • Identity & Access
  • Network Infrastructure
  • Zero-Day Vulnerabilities