ZDI-26-594: NVIDIA Megatron Bridge load_model_config Code Injection Remote Code Execution Vulnerability
NVIDIA Megatron Bridge load_model_config code injection flaw (CVE-2026-24251, CVSS 7.8) enables remote arbitrary code execution on affected installs.
ZDI-26-594 describes a code injection vulnerability in NVIDIA Megatron Bridge's load_model_config function, tracked as CVE-2026-24251 with CVSS 7.8. Exploitation allows remote attackers to execute arbitrary code on affected installations and requires user interaction. The advisory was published by the Zero Day Initiative on August 24, 2026.
- Code injection via load_model_config allows remote arbitrary code execution
- Requires user interaction via malicious page or file
- Tracked as CVE-2026-24251, CVSS 7.8; fix available through ZDI
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-24251 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. NVD description · AI analysis pending | 7.8 | <1% |
| — |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Megatron Bridge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24251.
This source does not provide full text. Read it at zerodayinitiative.com.