UEFI Password Bypass in NVIDIA DGX Spark
CVE-2026-47624
6MEDIUM
What is CVE-2026-47624?
NVIDIA DGX Spark is affected by a vulnerability in its UEFI firmware, allowing a privileged local user to bypass the password protection mechanism. This susceptibility can enable unauthorized access to critical system settings and configurations, posing a severe risk to system integrity and security. Exploiting this flaw requires local access, emphasizing the importance of physical security measures. Organizations utilizing NVIDIA DGX Spark should evaluate their security protocols to mitigate potential exploitation.
Affected Version(s)
DGX Spark UEFI 0 to 1.110.12