CVE-2026-47624: Medium severity Nvidia DGX Spark vulnerability
Published Aug 25, 2026
·Updated
NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.
Affected Software
1 affected component
Nvidia DGX Spark
Event History
Aug 25, 2026
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this vulnerability?
The affected product identified in the available data is NVIDIA DGX Spark. Exploitation requires a privileged local user, so it is not described as remotely exploitable.
2
What does an attacker need to exploit it?
An attacker needs local access and high privileges. No user interaction is required according to the provided CVSS vector.
3
What could a successful exploit allow?
A successful exploit may bypass UEFI administrator-password protection. The provided impact data indicates integrity impact, with no confidentiality or availability impact listed.