CVE-2026-24170: High severity Nvidia UFM Enterprise vulnerability
NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP requests. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an authenticated account?
The supplied information is inconsistent: the description says an authenticated user can exploit the issue, while the CVSS vector lists privileges required as none (PR:N). Treat the authentication requirement as unresolved until NVIDIA provides clarification.
What network position does an attacker need?
The CVSS vector identifies adjacent-network access (AV:A). The issue is associated with specially crafted HTTP requests to the UFM Enterprise web interface.
What could a successful attacker achieve?
Successful exploitation may result in code execution and privilege escalation. The reported impact includes high confidentiality, integrity, and availability effects.