CVE-2026-24167

Summary

NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure.

Affected Software

VendorProductVersion RangeStatus
NVIDIAUnified Fabric Manager Enterprise - GAAll GA versions prior to 6.24.1-5affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2025All LTS versions prior to 6.23.20-3affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2024All LTS versions prior to 6.19.15affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2023All LTS versions prior to 6.15.17affected

Weaknesses

  • CWE-77: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References