CVE-2026-24167: Command Injection
NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be an authenticated administrator and must be able to send a crafted API request to the UFM Enterprise user management component. The CVSS vector indicates adjacent-network attack access, low attack complexity, and no user interaction requirement.
What is the likely impact if exploitation succeeds?
Successful exploitation may allow command injection leading to code execution, privilege escalation, and information disclosure. The CVSS vector also indicates high potential impact to confidentiality, integrity, and availability.