Out-of-Bounds Write Vulnerability in NVIDIA DGX Spark Firmware
CVE-2026-24262

8.2HIGH

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-24262?

NVIDIA DGX Spark contains a vulnerability in its system firmware that allows a privileged attacker to execute an out-of-bounds write. If exploited, this could lead to various severe consequences, including unauthorized code execution, escalation of privileges, denial of service, unauthorized information disclosure, and potential data tampering. Organizations using NVIDIA DGX Spark should prioritize remediation to mitigate any associated security risks.

Affected Version(s)

DGX Spark UEFI 0 to 1.110.12

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.