Executive brief
NVIDIA UFM Enterprise is a network management platform used to monitor and configure high-performance computing fabrics. An authenticated user can bypass authorization controls in the web interface by sending specially crafted requests, potentially allowing them to execute arbitrary code and gain elevated system privileges.
Technical details
This vulnerability is an authentication/authorization bypass in the web interface authorization component of NVIDIA UFM Enterprise. An authenticated user can craft malicious HTTP requests to circumvent proper authentication checks. Successful exploitation allows an attacker to escalate privileges and achieve arbitrary code execution on the affected system. The vulnerability requires an attacker to already possess valid credentials and network access to the web interface. Patches are available from NVIDIA and should be applied to all affected versions of UFM Enterprise.
Affected products
- NVIDIA UFM Enterprise <UNKNOWN>
Timeline
- 2026-08-25: disclosed