Description
NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges.
Published: 2026-08-18
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The issue lies within the user management component of NVIDIA Cumulus Linux, where unprivileged users can exploit improper privilege management to gain higher privileges. This can lead to unauthorized control, allowing attackers to modify system configuration, compromise data integrity, and potentially disrupt network operations. The weakness is categorized as CWE-250, Privilege Escalation Through Improper Access Control.

Affected Systems

NVIDIA Cumulus Linux General Availability releases are affected. The vulnerability applies to all GA versions of the distribution as identified by NVIDIA.

Risk and Exploitability

The CVSS score of 7.8 reflects high severity, but the EPSS score is not available, suggesting limited public exploitation data. The vulnerability is not listed in the CISA KEV catalog. As the flaw involves user management, the attack likely requires local or network access to the device, possibly via console or management interface, and does not provide remote code execution on its own.

Generated by OpenCVE AI on August 18, 2026 at 19:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the NVIDIA Cumulus Linux patch that addresses the privilege management flaw.
  • Restrict or remove unnecessary unprivileged accounts and enforce least privilege for all users.
  • Disable or separate management interfaces from the rest of the network to limit potential attack paths.
  • Monitor system logs for unauthorized privilege changes to detect exploitation attempts.

Generated by OpenCVE AI on August 18, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges.
Weaknesses CWE-250
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-18T18:31:08.659Z

Reserved: 2026-01-21T19:09:32.732Z

Link: CVE-2026-24183

cve-icon Vulnrichment

Updated: 2026-08-18T18:31:00.811Z

cve-icon NVD

Status : Received

Published: 2026-08-18T19:16:45.520

Modified: 2026-08-18T19:16:45.520

Link: CVE-2026-24183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T19:30:04Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges