SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47624

MEDIUM · CVSS 6 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

NVIDIA DGX Spark is vulnerable due to a flaw in its UEFI implementation that allows a privileged local user to bypass administrator password protection, classified as CWE-693. This could enable unauthorized access to system settings and sensitive data, potentially compromising the integrity of the system. Organizations using NVIDIA DGX Spark should prioritize addressing this vulnerability to mitigate risks associated with unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-47624
Severity
MEDIUM
CVSS
6
EPSS
0.18%

Original NVD Description

NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.

Related CVEs

Other vulnerabilities affecting the same vendor(s)