Junglewise Threat Intelligence

CVE-2026-65128: NVIDIA Infrastructure Controller for Linux SQL injection

CVE-2026-65128 · Severity: high · CVSS 8.8 · Published 2026-09-22

Vendors: Nvidia.

Executive brief

NVIDIA Infrastructure Controller for Linux is a management tool for deploying and monitoring infrastructure. An attacker could exploit a SQL injection vulnerability to execute arbitrary code, modify data, disrupt service availability, or steal sensitive information from the system and connected infrastructure.

Technical details

The vulnerability is a SQL injection flaw in NVIDIA Infrastructure Controller for Linux that allows an attacker to inject malicious SQL commands. The attack vector and authentication requirements are not specified in the available advisory content, but successful exploitation could lead to code execution, data modification, denial of service, and information disclosure.

Affected products

  • NVIDIA Infrastructure Controller for Linux

Timeline

  • 2026-09-22: disclosed

References

Related threats