CVE-2026-47493

Summary

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for which it is not authorized. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

Affected Software

VendorProductVersion RangeStatus
NVIDIAVirtual GPU Manager595.71.03(All versions prior to and including vGPU 20.1)affected
NVIDIAVirtual GPU Manager580.159.01(All versions prior to and including vGPU 19.5)affected
NVIDIAVirtual GPU Manager596.38(All versions prior to and including vGPU 20.1)affected
NVIDIAVirtual GPU Manager582.51(All versions prior to and including vGPU 19.5)affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References