Junglewise Threat Intelligence

CVE-2026-65130: NVIDIA Infrastructure Controller for Linux OS command injection

CVE-2026-65130 · Severity: high · CVSS 8 · Published 2026-09-22

Vendors: Nvidia.

Executive brief

NVIDIA Infrastructure Controller for Linux is a system management tool used to administer Linux infrastructure. A command injection vulnerability allows attackers to execute arbitrary OS commands on affected systems, potentially leading to code execution, data compromise, denial of service, and unauthorized information access.

Technical details

An OS command injection vulnerability in NVIDIA Infrastructure Controller for Linux permits attackers to inject and execute arbitrary OS commands through unsanitized input. The vulnerability likely requires network access or local authentication; successful exploitation results in arbitrary code execution with controller privileges, compromising system integrity, confidentiality, and availability.

Affected products

  • NVIDIA Infrastructure Controller for Linux

Timeline

  • 2026-09-22: disclosed

References

Related threats