Executive brief
NVIDIA NVFlare Dashboard, a platform for federated machine learning, contains a critical security flaw in its user management system. An unauthenticated attacker can bypass security checks to gain unauthorized access to the dashboard. This could allow an attacker to steal sensitive data, modify system configurations, or execute malicious code, potentially compromising the entire machine learning environment.
Technical details
NVIDIA NVFlare Dashboard is vulnerable to an authorization bypass (CWE-639) within its user management and authentication system. The flaw stems from the system's reliance on user-controlled keys to determine authorization levels, allowing an unauthenticated remote attacker to manipulate these keys and bypass security controls. Successful exploitation grants the attacker the ability to perform privilege escalation, data tampering, and remote code execution. The vulnerability is addressed in NVFlare version 2.7.2.
Affected products
- NVIDIA NVFlare Dashboard < 2.7.2
Timeline
- 2026-04-28: disclosed
- 2026-04-28: advisory
- 2026-06-09: patched: Advisory updated with patch information