Firmware Vulnerability in NVIDIA DGX Spark Product
CVE-2026-24263

8.2HIGH

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-24263?

The NVIDIA DGX Spark product has a vulnerability in its firmware that can be exploited by a privileged attacker to trigger a NULL pointer dereference. Successful exploitation of this flaw can lead to severe consequences, including unauthorized code execution, escalation of user privileges, service disruptions, potential exposure of sensitive information, and the alteration of data integrity. It is crucial for users and organizations relying on this product to address the situation promptly to safeguard against potential threats.

Affected Version(s)

DGX Spark UEFI 0 to 1.110.12

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.