GPU VulnDB

Database/Firmware, BMC & network fabric

NVIDIA UFM Enterprise: crafted user-management API request lets an admin inject commands on the fabric manager

CVE-2026-24167Firmware, BMC & network fabriccurated

Impact

An authenticated administrator can send a crafted request to the user management component and have commands executed by UFM itself, per NVIDIA's advisory, leading to code execution, privilege escalation and information disclosure. UFM is the control point for an InfiniBand fabric: a host that runs it holds subnet manager authority, fabric topology and credentials for the switches it manages. Code execution there converts an account that was only supposed to administer UFM into control of the host, and from there into a position on the fabric that crosses every tenant sharing it. All supported branches are listed - GA and LTS 2023, 2024 and 2025.

Who can reach it

An authenticated user with administrative privileges on UFM, reaching the API from an adjacent network - in practice the management VLAN the fabric manager sits on. High privilege is required, so this is a privilege-boundary break inside the management plane rather than a remote entry point.

What to do

Update UFM Enterprise to the fixed build for your branch as listed in NVIDIA's advisory (GA, LTS 2023, LTS 2024, LTS 2025 are all affected); the record given here does not state the fixed version numbers, so read the advisory before scheduling. The upgrade restarts the UFM service, which briefly interrupts fabric management and monitoring but does not require touching compute nodes. Meanwhile, restrict who holds UFM administrator accounts and keep the UFM API off any network a tenant can reach.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.