# CVE-2026-47624

## Summary

- **CVE ID:** CVE-2026-47624
- **Severity:** MEDIUM
- **CVSS Score:** 6 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N)
- **CWE:** CWE-693
- **Published:** Aug 25, 2026
- **Last Modified:** Aug 26, 2026

## Description

NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.

## Affected Products

- NVIDIA — DGX Spark (0 to 1.110.12)

## References

- [CNA](https://nvd.nist.gov/vuln/detail/CVE-2026-47624)
- [CNA](https://www.cve.org/CVERecord?id=CVE-2026-47624)
- [CNA](https://github.com/NVIDIA/product-security/tree/main/2026/5867)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 7.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._