Junglewise Threat Intelligence

CVE-2026-47626: NVIDIA DGX Spark out-of-bounds write in system firmware

CVE-2026-47626 · Severity: high · CVSS 8.2 · Published 2026-08-25

Technologies: Nvidia Dgx Spark Uefi, Nvidia Dgx Spark. Vendors: Nvidia.

Executive brief

NVIDIA DGX Spark is a high-performance computing appliance used for AI and machine learning workloads. A vulnerability in its system firmware could allow a privileged attacker to write data outside intended memory boundaries, potentially leading to code execution, privilege escalation, or denial of service. This directly threatens the availability and integrity of critical AI infrastructure and any sensitive data processed on these systems.

Technical details

The vulnerability is an out-of-bounds write in DGX Spark's system firmware that requires privileged attacker access. This memory safety defect occurs in the firmware layer, a critical component that runs at the highest privilege level before the operating system. A successful exploit can lead to code execution at firmware level, privilege escalation, denial of service, information disclosure, and data tampering. The attack surface is limited to privileged users or accounts with direct hardware access, reducing but not eliminating risk in multi-tenant or untrusted personnel scenarios. Patched firmware versions should be available through NVIDIA's security updates.

Affected products

  • NVIDIA DGX Spark

Timeline

  • 2026-08-25: disclosed

References

Related threats