NVIDIA DGX OS Vulnerability in Factory Provisioning Process Leads to Security Risks
CVE-2026-24218

8.1HIGH

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-24218?

The NVIDIA DGX OS suffers from a vulnerability in its factory provisioning process, where the cloning of a base image leads to multiple systems sharing the same SSH host keys. This shared cryptographic identifier poses a significant security risk as it allows for host impersonation and potential man-in-the-middle attacks. Exploiting this vulnerability can lead to unauthorized code execution, data manipulation, privilege escalation, information disclosure, and even denial of service, highlighting the urgent need for security measures in provisioning processes.

Affected Version(s)

DGX Spark NVIDIA DGX OS 0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.