CVE-2026-24170

8.8

NVIDIA · Unified Fabric Manager Enterprise

NVIDIA UFM Enterprise contains an improper authentication vulnerability in the web interface authorization component that can be triggered via specially crafted HTTP requests.

Executive summary

A vulnerability in the NVIDIA Unified Fabric Manager Enterprise web interface allows for improper authentication, posing a critical risk of unauthorized access and system compromise.

Vulnerability

This vulnerability involves improper authentication within the web interface authorization component. Despite descriptions suggesting authenticated use, the CVSS vector (PR:N) indicates that the attacker does not require prior authentication to exploit this flaw via the network.

Business impact

Successful exploitation of this flaw allows an attacker to bypass authentication mechanisms, potentially leading to full system compromise. With a CVSS score of 8.8, this vulnerability presents a high risk to data confidentiality, integrity, and availability, which could result in significant operational disruption and unauthorized administrative access to the fabric management environment.

Remediation

Immediate Action: Update the NVIDIA UFM Enterprise software to the versions specified in the vendor security advisory (6.24.1-5, 6.23.20-3, 6.19.15, or 6.15.17 depending on the branch).

Proactive Monitoring: Monitor network access logs for unusual HTTP request patterns targeting the UFM web interface and track unauthorized access attempts or suspicious session activity.

Compensating Controls: Restrict network access to the UFM web interface to trusted management subnets and deploy a Web Application Firewall (WAF) to filter malicious or malformed HTTP requests.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high CVSS score and the potential for total system compromise, organizations should prioritize patching their UFM Enterprise instances immediately. Following the vendor update path is the only effective way to remediate this authentication vulnerability and prevent unauthorized access.

More NVIDIA CVEs