# CVE-2026-24166

## Summary

- **CVE ID:** CVE-2026-24166
- **Severity:** MEDIUM
- **CVSS Score:** 5.1 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-321
- **Published:** Aug 25, 2026
- **Last Modified:** Aug 25, 2026

## Description

NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges.

## Affected Products

- NVIDIA — Unified Fabric Manager Enterprise - GA (All GA versions prior to 6.24.1-5)
- NVIDIA — Unified Fabric Manager Enterprise - LTS 2025 (All LTS versions prior to 6.23.20-3)
- NVIDIA — Unified Fabric Manager Enterprise - LTS 2024 (All LTS versions prior to 6.19.15)
- NVIDIA — Unified Fabric Manager Enterprise - LTS 2023 (All LTS versions prior to 6.15.17)

## References

- [CNA](https://nvd.nist.gov/vuln/detail/CVE-2026-24166)
- [CNA](https://www.cve.org/CVERecord?id=CVE-2026-24166)
- [CNA](https://github.com/NVIDIA/product-security/tree/main/2026/5809)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._