CVE-2026-24178: NVIDIA Nvflare

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.

Affected products

  • NVIDIA Nvflare: before 2.7.2 (fixed in 2.7.2)

Published 2026-04-28. Last modified 2026-06-17.