UEFI Password Bypass in NVIDIA DGX Spark
CVE-2026-47624

6MEDIUM

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-47624?

NVIDIA DGX Spark is affected by a vulnerability in its UEFI firmware, allowing a privileged local user to bypass the password protection mechanism. This susceptibility can enable unauthorized access to critical system settings and configurations, posing a severe risk to system integrity and security. Exploiting this flaw requires local access, emphasizing the importance of physical security measures. Organizations utilizing NVIDIA DGX Spark should evaluate their security protocols to mitigate potential exploitation.

Affected Version(s)

DGX Spark UEFI 0 to 1.110.12

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.