Description
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
Published: 2026-08-25
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privileged Code Execution
Action: Apply Firmware Patch
AI Analysis

Impact

NVIDIA DGX Spark firmware contains an out-of-bounds write vulnerability that can be triggered by a privileged attacker. Exploitation may allow arbitrary code execution, privilege escalation, denial of service, information disclosure, and data tampering, potentially compromising the entire system.

Affected Systems

The affected product is NVIDIA DGX Spark. No specific firmware version ranges are disclosed in the CVE data, so all current releases are presumed vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability; the EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is a local privileged attacker who can interact with the system firmware, giving them the ability to execute arbitrary code or manipulate data with high privileges.

Generated by OpenCVE AI on August 25, 2026 at 21:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DGX Spark firmware to the latest NVIDIA release that addresses the out-of-bounds write flaw.
  • Limit access to privileged firmware modification interfaces, ensuring only trusted administrators can perform firmware updates.
  • Enable precise logging of firmware modification attempts and monitor logs for suspicious activity.
  • Maintain up-to-date backups of critical system configuration and data before applying firmware changes.

Generated by OpenCVE AI on August 25, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia dgx Spark Uefi
CPEs cpe:2.3:h:nvidia:dgx_spark:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:dgx_spark_uefi:*:*:*:*:*:*:*:*
Vendors & Products Nvidia dgx Spark Uefi

Tue, 25 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in NVIDIA DGX Spark Firmware Enables Privileged Code Execution

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in NVIDIA DGX Spark Firmware Enables Privileged Code Execution
First Time appeared Nvidia
Nvidia dgx Spark
Vendors & Products Nvidia
Nvidia dgx Spark

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Nvidia Dgx Spark Dgx Spark Uefi
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-26T03:56:35.686Z

Reserved: 2026-05-19T19:55:52.529Z

Link: CVE-2026-47626

cve-icon Vulnrichment

Updated: 2026-08-25T19:55:34.845Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T17:17:14.150

Modified: 2026-09-09T13:22:35.350

Link: CVE-2026-47626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:15:13Z

Weaknesses