CVE-2026-24170 affects NVIDIA UFM Enterprise, specifically its web interface authorization component. An authenticated user can exploit this vulnerability by sending specially crafted HTTP requests, triggering improper authentication behavior. Successful exploitation may lead to arbitrary code execution and escalation of privileges on the affected system. The vulnerability requires an authenticated session to exploit, slightly limiting the attack surface but not eliminating the risk. NVIDIA has published an advisory through their product-security GitHub repository. The flaw is catalogued by both NVD and CVE.org. Given the potential for code execution and privilege escalation, the vulnerability is rated high criticality. Organizations using NVIDIA UFM Enterprise should review the vendor advisory and apply patches promptly.