CVE-2026-24168

Summary

NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API requests. A successful exploit of this vulnerability may lead to code execution, escalation of privileges and information disclosure.

Affected Software

VendorProductVersion RangeStatus
NVIDIAUnified Fabric Manager Enterprise - GAAll GA versions prior to 6.24.1-5affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2025All LTS versions prior to 6.23.20-3affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2024All LTS versions prior to 6.19.15affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2023All LTS versions prior to 6.15.17affected

Weaknesses

  • CWE-77: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References