NVIDIA Cumulus Linux: Improper privilege management in the user-management component lets an unprivileged switch user
CVE-2026-24183NVIDIA / GPU stackcurated
Impact
Improper privilege management in the user-management component lets an unprivileged switch user escalate to full switch administration.
Who can reach it
Local on the switch, unprivileged. Anyone with any shell account on the Cumulus switch - including read-only monitoring accounts.
What to do
Upgrade Cumulus Linux per bulletin 5817. Cost: switch reboot and link flap; sequence leaf-by-leaf so the fabric keeps ECMP paths. Audit who actually has shell on your switches while you are at it.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.