CVE-2026-65128
8.8NVIDIA · Infrastructure Controller
NVIDIA Infrastructure Controller for Linux is vulnerable to SQL injection, potentially allowing authenticated attackers to execute code, tamper with data, or cause a denial of service.
Executive summary
A high-severity SQL injection vulnerability in the NVIDIA Infrastructure Controller allows authenticated attackers to compromise system integrity and availability.
Vulnerability
The software fails to properly neutralize special elements used in SQL commands, which allows an attacker with low privileges to perform SQL injection attacks. The vulnerability is exploitable over the network without user interaction.
Business impact
The ability for an attacker to perform SQL injection poses a significant risk to organizational data and operational continuity. Successful exploitation can lead to unauthorized code execution and full database compromise, potentially resulting in the loss of sensitive information, data corruption, and prolonged service outages. With a CVSS score of 8.8, this vulnerability represents a significant threat to the security posture of systems utilizing this controller.
Remediation
Immediate Action: Monitor official NVIDIA security bulletins for the release of a patched version and apply it immediately upon availability.
Proactive Monitoring: Review database access logs for unusual query patterns and implement strict database access controls to limit the potential impact of an injection attempt.
Compensating Controls: Deploy a Web Application Firewall (WAF) or database-level firewall configured to detect and block SQL injection syntax in traffic directed at the controller.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for severe impact, security teams must prioritize the remediation of this vulnerability as soon as the vendor provides a patch. While no active exploitation is currently observed, the capability for remote attackers to execute arbitrary SQL commands necessitates immediate defensive hardening of all affected infrastructure components.
More NVIDIA CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section