CVE-2026-65121

8.2

NVIDIA · Infrastructure Controller

NVIDIA Infrastructure Controller for Linux contains an improper authentication vulnerability that may allow unauthenticated attackers to escalate privileges and access sensitive data.

Executive summary

A critical authentication flaw in the NVIDIA Infrastructure Controller for Linux exposes systems to unauthorized privilege escalation and information disclosure.

Vulnerability

This vulnerability, categorized as CWE-287 (Improper Authentication), allows an unauthenticated network adjacent attacker to bypass standard security checks. The flaw leverages the authentication mechanism to facilitate unauthorized access to system resources.

Business impact

The potential for privilege escalation and data tampering poses a severe risk to organizational integrity. Given the CVSS score of 8.2, this vulnerability could allow attackers to gain administrative control over the infrastructure controller, leading to unauthorized access to critical network data and potential disruption of operational services.

Remediation

Immediate Action: Review the official NVIDIA security bulletin at the provided GitHub reference and apply the recommended security updates as soon as they become available.

Proactive Monitoring: Monitor system access logs and network traffic for suspicious authentication attempts or unauthorized access patterns targeting the controller interface.

Compensating Controls: Restrict network access to the Infrastructure Controller to trusted segments only, and implement strict firewall rules to limit exposure to the management interface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing the NVIDIA Infrastructure Controller must prioritize the identification of affected versions within their environment. Since a patch is currently not explicitly identified in the provided data, teams should maintain close watch on the NVIDIA product security repository and prepare to deploy updates immediately upon release to prevent potential exploitation.

More NVIDIA CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources