Junglewise Threat Intelligence

CVE-2026-24183: NVIDIA Cumulus Linux privilege escalation in user management

CVE-2026-24183 · Severity: high · CVSS 7.8 · Published 2026-08-18

Vendors: Nvidia.

Executive brief

NVIDIA Cumulus Linux is a network operating system used in data center switches and infrastructure. The product contains a flaw in user account management that allows an unprivileged user to escalate their privileges to gain administrative control of the system. Successful exploitation could allow an attacker to take full control of critical network infrastructure.

Technical details

The vulnerability is a privilege escalation flaw located in the user management component of Cumulus Linux, stemming from improper privilege management controls. An unprivileged, authenticated local user can exploit this weakness to elevate their access level without requiring additional system compromises. The attack requires local system access but no special prerequisites beyond standard user credentials. Successful exploitation grants the attacker administrative privileges, enabling complete system control. Patches are expected to be available through NVIDIA's security bulletin 5817 published in August 2026.

Affected products

  • NVIDIA Cumulus Linux

Timeline

  • 2026-08-18: disclosed

References

Related threats