CVE-2026-24166
Received Received - Intake

NVIDIA UFM Enterprise Session Key Information Disclosure

Vulnerability report for CVE-2026-24166, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: NVIDIA Corporation

Description

NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
nvidia unified_fabric_manager to 6.24.1-5 (exc)
nvidia unified_fabric_manager to 6.23.20-3 (exc)
nvidia unified_fabric_manager to 6.19.15 (exc)
nvidia unified_fabric_manager to 6.15.17 (exc)
nvidia ufm_enterprise *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in NVIDIA UFM Enterprise involves a hard-coded cryptographic key in the session management component. An attacker could exploit this to extract sensitive information, potentially leading to information disclosure and privilege escalation.

Detection Guidance

Detection of CVE-2026-24166 requires checking for affected versions of NVIDIA UFM Enterprise software. Verify if your system runs UFM Enterprise versions prior to 6.24.1-5 (GA), 6.23.20-3 (LTS 2025), 6.19.15 (LTS 2024), or 6.15.17 (LTS 2023). Use commands like 'ufm version' or check installed packages via package managers (e.g., 'dpkg -l | grep ufm' for Debian-based systems).

Inspect logs for unusual session activity or cryptographic key usage. Monitor network traffic for unauthorized access attempts to UFM services. Ensure no hard-coded keys are present in configuration files or binaries.

Impact Analysis

An attacker could exploit this to access sensitive data or gain higher privileges in the system. This may compromise confidentiality and allow unauthorized actions.

Compliance Impact

The vulnerability in NVIDIA UFM Enterprise involves a hard-coded cryptographic key that could allow attackers to extract sensitive information and escalate privileges. This could lead to unauthorized access to personal or health data, which may violate GDPR (General Data Protection Regulation) due to insufficient protection of personal data, and HIPAA (Health Insurance Portability and Accountability Act) if health-related data is compromised.

Mitigation Strategies

Update NVIDIA UFM Enterprise to versions GA 6.24.1-5 or later, LTS 2025 6.23.20-3 or later, LTS 2024 6.19.15 or later, or LTS 2023 6.15.17 or later to address the hard-coded cryptographic key issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24166. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart