Executive brief
NVIDIA UFM Enterprise is a fabric management system used to monitor and administer high-performance computing and storage networks. An authenticated administrator can inject arbitrary commands through a crafted API request targeting the user management component, potentially leading to unauthorized code execution, privilege escalation, and sensitive information disclosure on the management system.
Technical details
The vulnerability is a command injection flaw in the user management API component of NVIDIA UFM Enterprise. It requires authentication as an administrator and is triggered by sending a specially crafted API request. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the UFM service, potentially leading to full system compromise, escalation to higher privilege levels, and exfiltration of configuration and monitoring data. The vulnerability is network-accessible via the API interface.
Affected products
- NVIDIA UFM Enterprise
Timeline
- 2026-08-25: disclosed