Junglewise Threat Intelligence

CVE-2026-24170: NVIDIA UFM Enterprise authentication bypass in web interface

CVE-2026-24170 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Nvidia UFM Enterprise. Vendors: Nvidia.

Executive brief

NVIDIA UFM Enterprise is a network management platform used to monitor and configure high-performance computing fabrics. An authenticated user can bypass authorization controls in the web interface by sending specially crafted requests, potentially allowing them to execute arbitrary code and gain elevated system privileges.

Technical details

This vulnerability is an authentication/authorization bypass in the web interface authorization component of NVIDIA UFM Enterprise. An authenticated user can craft malicious HTTP requests to circumvent proper authentication checks. Successful exploitation allows an attacker to escalate privileges and achieve arbitrary code execution on the affected system. The vulnerability requires an attacker to already possess valid credentials and network access to the web interface. Patches are available from NVIDIA and should be applied to all affected versions of UFM Enterprise.

Affected products

  • NVIDIA UFM Enterprise <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats