Junglewise Threat Intelligence

CVE-2026-65117: NVIDIA Infrastructure Controller for Linux hard-coded password

CVE-2026-65117 · Severity: medium · CVSS 5 · Published 2026-09-22

Vendors: Nvidia.

Executive brief

NVIDIA Infrastructure Controller for Linux uses a hard-coded password that an attacker could exploit to gain unauthorized access. Successful exploitation could allow tampering with system data, disrupting service availability, or stealing sensitive information from managed infrastructure.

Technical details

The vulnerability involves use of a hard-coded password in NVIDIA Infrastructure Controller for Linux, allowing authentication bypass without legitimate credentials. An attacker with network access can exploit this to gain control of the controller, enabling data tampering, denial of service, and information disclosure. A patch is expected from NVIDIA.

Affected products

  • NVIDIA Infrastructure Controller for Linux

Timeline

  • 2026-09-22: disclosed

References

Related threats