CVE-2026-24168: Command Injection
NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API requests. A successful exploit of this vulnerability may lead to code execution, escalation of privileges and information disclosure.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authenticated to NVIDIA UFM Enterprise and already have administrative privileges. Exploitation is performed through crafted requests to the IBDiagnet API.
What impact could successful exploitation have?
Successful command injection may allow code execution, privilege escalation, and disclosure of information. The listed CVSS vector indicates high impact to confidentiality, integrity, and availability.
Is this exploitable remotely without access to the product?
The provided CVSS vector lists adjacent-network attack vector and high privileges required. The available information does not indicate that unauthenticated or Internet-based exploitation is possible.