GPU VulnDB

Database/Firmware, BMC & network fabric

NVIDIA UFM Enterprise: code injection via the plugin management API from a low-privileged account

CVE-2026-24169Firmware, BMC & network fabriccurated

Impact

A crafted request to UFM Enterprise's plugin management API lets an authenticated low-privilege user inject code, which NVIDIA says may lead to code execution, privilege escalation and information disclosure. UFM is the management brain for an InfiniBand fabric: an attacker who gets execution there is inside the system that enumerates, configures and monitors the interconnect every training job depends on, and that holds fabric-wide topology and credentials. A read-only or operator-tier UFM account - the kind handed out for monitoring - is enough to cross into full control of the host. All four supported branches are listed as affected: GA and LTS 2023, 2024 and 2025.

Who can reach it

An authenticated user with low privileges on UFM Enterprise, reaching the plugin management API from the adjacent network (CVSS AV:A, PR:L). In practice, anyone with a UFM login on the management VLAN.

What to do

Upgrade UFM Enterprise to the fixed build for your branch (GA, LTS 2025, LTS 2024 or LTS 2023) as listed in NVIDIA bulletin 5809 - the NVD record does not carry the version numbers, so read the bulletin for your branch rather than assuming. The upgrade restarts the UFM services; if this UFM instance also runs the subnet manager, schedule it alongside an SM failover to the standby so the fabric is not left unmanaged. Until patched, audit who holds low-privilege UFM accounts and keep the UFM API off any network reachable by tenants.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.