Out-of-Bounds Write Vulnerability in NVIDIA DGX Spark Firmware
CVE-2026-47626

8.2HIGH

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-47626?

The NVIDIA DGX Spark firmware has a security vulnerability that allows for out-of-bounds write operations. An attacker with elevated privileges could exploit this flaw, potentially leading to unauthorized code execution, escalation of privileges, denial of service, information disclosure, and data integrity issues. This critical issue underlines the importance of prompt software updates and security patches to protect against such exploits.

Affected Version(s)

DGX Spark UEFI 0 to 1.110.12

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.