AI analysis
CVE-2026-65126 is a behavioral workflow enforcement flaw (CWE-841) in the NVIDIA Infrastructure Controller for Linux. The vulnerability is triggered by an attacker with low-privilege access (PR:L) and requires a high-complexity attack chain (AC:H) to exploit. A successful exploit could lead to data tampering, denial of service, and information disclosure, though the impact is limited (C:L/I:L/A:L). The flaw affects NVIDIA's enterprise infrastructure management software. Public proof-of-concept code is not known, and it is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Monitor NVIDIA security bulletins for specific patched versions of the Infrastructure Controller for Linux. If deploying, ensure strict network access controls (restrict to management interfaces only) and audit user permissions to minimize risk from a low-privileged attacker.
Affected
| NVIDIA Infrastructure Controller for Linux | — |
Estimated exposure
moderateunknown; likely in the thousands to tens of thousands of installations globally among enterprise and cloud customers — NVIDIA Infrastructure Controller is a component within NVIDIA's enterprise AI infrastructure stack (e.g., DGX, Base Command), limiting its deployment to large organizations and cloud service providers rather than broad consumer use.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.