CVE-2026-24262: High severity Nvidia DGX Spark vulnerability
Published Aug 25, 2026
·Updated
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
Affected Software
3 affected components
Nvidia DGX Spark
All of the following
Nvidia Dgx Spark Uefi<1.110.13
Nvidia DGX Spark
Event History
Aug 25, 2026
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access is required to exploit this issue?
Exploitation requires local access and high privileges on the affected system. It is not scored as remotely exploitable or requiring user interaction.
2
Can exploitation affect components beyond the initially compromised security authority?
Yes. The CVSS vector indicates scope changed (S:C), meaning a successful exploit can affect resources beyond the vulnerable component's original security authority.