NVIDIA Infrastructure Controller Hit by 14 Flaws Enabling Code Execution and Privilege Escalation
NVIDIA patches 14 vulnerabilities in its Infrastructure Controller, including a critical CVSS 9.8 hard-coded credentials flaw enabling unauthenticated remote privilege escalation.
NVIDIA released version 2.0 of its Infrastructure Controller to patch 14 vulnerabilities in its Linux-based management software. The most severe flaw, CVE-2026-65113, is a critical hard-coded credentials vulnerability with a CVSS score of 9.8 that allows unauthenticated remote attackers to escalate privileges, modify data, and disrupt services. The update also addresses high-severity issues like SQL injection (CVE-2026-65128) and missing authentication (CVE-2026-65114), among others affecting versions 0 through 1.9.
- NVIDIA Infrastructure Controller version 2.0 patches 14 vulnerabilities, including a critical hard-coded credentials flaw (CVE-2026-65113, CVSS 9.8).
- Vulnerabilities allow for code execution, privilege escalation, data manipulation, denial of service, and information disclosure.
- The critical flaw can be exploited remotely without authentication.
- Affected versions are 0 through 1.9; users are advised to update from GitHub.
Vulnerabilities mentionedAll →
- CVE-2026-651139.8—Hard-Coded Credentials in NVIDIA Infrastructure Controller for Linuxpublished · NVIDIA Infrastructure Controller for Linux+9 related
- CVE-2026-651187.5—Improper Certificate Validation in NVIDIA Infrastructure Controller for Linuxpublished · NVIDIA Infrastructure Controller for Linux+3 related
Full article549 words · extracted from gbhackers.com · click to collapse
NVIDIA has released version 2.0 of its Infrastructure Controller to address 14 vulnerabilities found in its Linux-based infrastructure management software.
This update includes a critical flaw involving hard-coded credentials and multiple issues that could allow for code execution, privilege escalation, data manipulation, denial of service, and information disclosure.
NVIDIA released the initial security bulletin on September 22, 2026, and it affects NVIDIA Infrastructure Controller versions 0 through 1.9.
NVIDIA advises organizations to either clone or update the software from its GitHub repository to version 2.0 or later. The vulnerabilities range from critical to medium severity, with CVSS v3.1 scores as high as 9.8.
Critical Hard-Coded Credentials Flaw
The most severe issue, tracked as CVE-2026-65113, is a hard-coded credentials vulnerability rated 9.8 out of 10. This flaw can be exploited remotely without authentication or user interaction, potentially allowing an attacker to escalate privileges, modify data, disrupt services, and access sensitive information.
Additionally, NVIDIA has fixed CVE-2026-65128, which is an SQL injection vulnerability with a CVSS score of 8.8. Although exploitation requires low privileges, a successful attack could lead to code execution and compromise the confidentiality, integrity, and availability of affected deployments.
This update also addresses several authentication-related weaknesses. CVE-2026-65114 involves missing authentication for a crucial function, while CVE-2026-65121 is an improper authentication issue that could allow for privilege escalation.
These vulnerabilities highlight the importance of restricting access to administrative interfaces and isolating management-plane services from untrusted networks.
CVE-2026-65130 is an OS command injection vulnerability rated at 8.0. While it requires high privileges and has a high attack complexity, exploitation could result in arbitrary code execution, privilege escalation across a security boundary, data tampering, service disruption, and data exposure.
The update also addresses two flaws related to improper certificate validation: CVE-2026-65118, rated 7.5, and CVE-2026-65129, rated 6.7. These defects can undermine trust verification during communications, creating opportunities for attackers with adjacent network access to intercept, manipulate, or expose data.
Other identified weaknesses include external control of file names or paths, XML injection, failures in workflow enforcement, hard-coded passwords, uncontrolled resource consumption, and the exposure of uncleared debug information.
CVE Details
| CVE | Vulnerability type | CVSS | Severity | Potential impact |
|---|---|---|---|---|
| CVE-2026-65113 | Hard-coded credentials | 9.8 | Critical | Privilege escalation, data tampering, DoS, information disclosure |
| CVE-2026-65128 | SQL injection | 8.8 | High | Code execution, data tampering, DoS, information disclosure |
| CVE-2026-65114 | Missing authentication | 8.3 | High | Data tampering, DoS, information disclosure |
| CVE-2026-65121 | Improper authentication | 8.2 | High | Privilege escalation, data tampering, information disclosure |
| CVE-2026-65130 | OS command injection | 8.0 | High | Code execution, data tampering, DoS, information disclosure |
| CVE-2026-65118 | Improper certificate validation | 7.5 | High | Data tampering, DoS, information disclosure |
| CVE-2026-65129 | Improper certificate validation | 6.7 | Medium | Data tampering, DoS, information disclosure |
| CVE-2026-65125 | External file/path control | 6.6 | Medium | Code execution, privilege escalation, tampering, DoS |
| CVE-2026-65115 | Uncontrolled resource consumption | 6.5 | Medium | Denial of service |
| CVE-2026-65112 | Uncontrolled resource consumption | 6.5 | Medium | Denial of service |
| CVE-2026-65124 | XML injection | 5.9 | Medium | Data tampering, denial of service |
| CVE-2026-65126 | Improper workflow enforcement | 5.0 | Medium | Data tampering, DoS, information disclosure |
| CVE-2026-65117 | Hard-coded password | 5.0 | Medium | Data tampering, DoS, information disclosure |
| CVE-2026-65127 | Uncleared debug information | 4.1 | Medium | Information disclosure |
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.