Junglewise Threat Intelligence

CVE-2026-24168: NVIDIA UFM Enterprise command injection in IBDiagnet API

CVE-2026-24168 · Severity: medium · CVSS 6.8 · Published 2026-08-25

Technologies: Nvidia UFM Enterprise. Vendors: Nvidia.

Executive brief

NVIDIA UFM Enterprise is a fabric management system used to monitor and administer high-performance computing infrastructure. An authenticated administrator can inject malicious commands through the IBDiagnet API, potentially leading to arbitrary code execution, privilege escalation, and unauthorized access to sensitive system information.

Technical details

The vulnerability is a command injection flaw in the IBDiagnet API component of NVIDIA UFM Enterprise. An authenticated attacker with administrative privileges can craft malicious API requests containing shell metacharacters to inject arbitrary commands. The vulnerability requires authentication and administrative privileges, but successful exploitation allows arbitrary code execution with the privileges of the UFM Enterprise service, potentially leading to complete system compromise and access to sensitive fabric management data.

Affected products

  • NVIDIA UFM Enterprise

Timeline

  • 2026-08-25: disclosed

References

Related threats