Junglewise Threat Intelligence

CVE-2026-24169: NVIDIA UFM Enterprise code injection in plugin management API

CVE-2026-24169 · Severity: high · CVSS 8 · Published 2026-08-25

Technologies: Nvidia UFM Enterprise. Vendors: Nvidia.

Executive brief

NVIDIA UFM Enterprise is a fabric management system used to administer high-performance computing and data center networks. An authenticated user with low privileges can inject and execute arbitrary code through the plugin management API, potentially compromising the entire system, gaining administrative access, and stealing sensitive network or configuration data.

Technical details

This vulnerability is a code injection flaw in the plugin management API of NVIDIA UFM Enterprise. An authenticated user with low privileges can craft a specially malformed API request to inject arbitrary code. The attack requires valid credentials but does not require special network position or user interaction. Successful exploitation leads to arbitrary code execution with the privileges of the UFM service, enabling privilege escalation and information disclosure. Patches should be available from NVIDIA for affected versions.

Affected products

  • NVIDIA UFM Enterprise <UNKNOWN>

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: advisory

References

Related threats