Description
NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.
Published: 2026-08-25
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

NVIDIA DGX Spark has a firmware weakness in UEFI that allows a local user with sufficient permissions to bypass the administrator password guard. This breach removes the intended restriction on UEFI configuration and could enable unauthorized changes to boot or firmware settings that would normally require administrator authentication.

Affected Systems

The vulnerability affects NVIDIA DGX Spark platforms. No specific firmware or platform version numbers are provided in the listing.

Risk and Exploitability

The CVSS score of 6 indicates moderate severity, while the EPSS score is not available and the vulnerability is not currently listed in CISA KEV. Based on the description, it is inferred that the attack vector requires local physical or privileged access to the device, which limits the exposed threat surface but still poses a significant risk if an insider or attacker gains local control.

Generated by OpenCVE AI on August 25, 2026 at 21:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DGX Spark firmware to the latest release that addresses the UEFI password bypass flaw.
  • Restrict physical and local access to the DGX Spark and enforce console lockdown so that only authorized personnel can interact with the system.
  • Configure the UEFI settings to require authenticated access for all firmware changes and disable legacy boot mechanisms that could circumvent the administrator password.

Generated by OpenCVE AI on August 25, 2026 at 21:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia dgx Spark Uefi
CPEs cpe:2.3:h:nvidia:dgx_spark:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:dgx_spark_uefi:*:*:*:*:*:*:*:*
Vendors & Products Nvidia dgx Spark Uefi

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title UEFI Password Bypass via Local Privilege Escalation

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title UEFI Password Bypass via Local Privilege Escalation

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia dgx Spark
Vendors & Products Nvidia
Nvidia dgx Spark

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Nvidia Dgx Spark Dgx Spark Uefi
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-26T19:46:56.881Z

Reserved: 2026-05-19T19:55:52.529Z

Link: CVE-2026-47624

cve-icon Vulnrichment

Updated: 2026-08-26T19:46:51.311Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T17:17:13.590

Modified: 2026-09-09T13:23:00.157

Link: CVE-2026-47624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:15:13Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure