CVE-2026-24186

8.8

NVIDIA · FLARE SDK

NVIDIA FLARE SDK is vulnerable to deserialization of untrusted data in FOBS, allowing an authenticated attacker to potentially achieve remote code execution via malicious FOBS-encoded messages.

Executive summary

A critical deserialization vulnerability in the NVIDIA FLARE SDK could allow an authenticated attacker to execute arbitrary code on the affected system.

Vulnerability

The software fails to properly sanitize input during the deserialization of FOBS-encoded data. An authenticated attacker can leverage this flaw by sending a specially crafted message to the vulnerable component to trigger code execution.

Business impact

Successful exploitation of this flaw poses a severe risk to organizational infrastructure, as it grants an attacker the ability to execute arbitrary code. With a CVSS score of 8.8, this vulnerability is classified as High severity and could result in full system compromise, unauthorized data access, and potential lateral movement within the network.

Remediation

Immediate Action: Upgrade to NVIDIA FLARE SDK version 2.7.2 or later to apply the necessary security patches.

Proactive Monitoring: Monitor network traffic and application logs for unusual FOBS-encoded payloads or unexpected process execution patterns originating from the SDK.

Compensating Controls: Restrict access to the NVIDIA FLARE SDK environment to authorized personnel only to limit the exposure of the vulnerable deserialization endpoint.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution, this vulnerability represents a significant security risk to any environment utilizing the NVIDIA FLARE SDK. Administrators should prioritize the update to version 2.7.2 immediately to remediate the underlying flaw and prevent potential exploitation.

More NVIDIA CVEs

Sources