Junglewise Threat Intelligence

CVE-2026-24185: NVIDIA NVOS SSH server authentication bypass in PKA-only mode

CVE-2026-24185 · Severity: high · CVSS 7.1 · Published 2026-08-18

Vendors: Nvidia.

Executive brief

NVIDIA NVOS is the operating system for network switches that manage data center traffic and connectivity. This vulnerability in the SSH (remote administrative access) component creates an alternative login path when a security feature called PKA-only mode is enabled. If administrators do not change the default password as instructed, attackers could gain unauthorized remote access and take full control of the network switch.

Technical details

This vulnerability exists in the SSH server configuration component of NVIDIA NVOS when PKA-only mode is enabled. The flaw allows an alternative authentication path to be inadvertently enabled, which, if combined with failure to replace the default password per NVIDIA's recommendations, provides unauthorized access. The attack vector is network-based and requires no user interaction. A successful exploit enables privilege escalation on the affected network switch. Patches are expected to be available through NVIDIA's security advisory process.

Affected products

  • NVIDIA NVOS unspecified

Timeline

  • 2026-08-18: disclosed

References