CVE-2026-65128: SQL Injection
Published Sep 22, 2026
·Updated
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Affected Software
1 affected component
Nvidia Infrastructure Controller for Linux
Event History
Sep 22, 2026
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Deployments of NVIDIA Infrastructure Controller for Linux that are reachable over the network are in scope. The CVSS vector indicates an attacker needs low-level privileges, so unauthenticated access alone is not indicated.
2
What conditions does exploitation require?
The issue has network attack vector, low attack complexity, and requires no user interaction. An attacker must already have low privileges before exploiting the SQL injection vulnerability.