CVE-2026-24169

Summary

NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure.

Affected Software

VendorProductVersion RangeStatus
NVIDIAUnified Fabric Manager Enterprise - GAAll GA versions prior to 6.24.1-5affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2025All LTS versions prior to 6.23.20-3affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2024All LTS versions prior to 6.19.15affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2023All LTS versions prior to 6.15.17affected

Weaknesses

  • CWE-77: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References