CVE-2026-24166: Medium severity Nvidia UFM Enterprise vulnerability
Published Aug 25, 2026
·Updated
NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges.
Affected Software
1 affected component
Nvidia UFM Enterprise
Event History
Aug 25, 2026
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The vulnerability is locally exploitable. The attacker does not need privileges or user interaction, but exploitation has high attack complexity.
2
What is the potential impact if exploitation succeeds?
A successful exploit may disclose information and could enable escalation of privileges.