CRITICAL🇵🇱 Wersja polska

CVE-2026-24178

CVSS 9.8v3.1pub. 2026-04-28upd. 2026-05-04

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.

🤖 AI Analysis
How it works

The vulnerability (CWE-639) is based on the fact that the authorization system relies on a key that can be controlled by an attacker on the client side. An unauthorized attacker can manipulate this key in such a way as to gain access to resources or functions reserved for authorized users. The attack does not require any authentication, account possession, or interaction from the victim, and can be conducted remotely over the network.

Impact

An attacker can achieve privilege escalation, data modification (data tampering), disclosure of sensitive information (information disclosure), remote code execution (RCE), and denial of service (DoS) — potentially gaining complete control over the system.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references (https://nvidia.custhelp.com/app/answers/detail/a_id/5819). Until the fix is implemented, it is recommended to restrict network access to the NVFlare Dashboard interface exclusively to trusted hosts and internal networks.

Who is affected

NVIDIA NVFlare Dashboard running on Apple macOS and Linux (Linux Kernel); specific versions indicated in the manufacturer's references (https://nvidia.custhelp.com/app/answers/detail/a_id/5819)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apple macOS

    OS
    Apple
    all versions
  • Linux Kernel

    OS
    Linux
    all versions
  • Nvidia Nvflare

    APP
    Nvidia
    < 2.7.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth BypassLPEDoS
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2025-31201CRITICAL9.8⚠ KEVPL ✓same product

Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach