XML Injection Vulnerability in NVIDIA Infrastructure Controller for Linux
CVE-2026-65124

5.9MEDIUM

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
22 September 2026

What is CVE-2026-65124?

The NVIDIA Infrastructure Controller for Linux is susceptible to an XML injection vulnerability, which could be exploited by an attacker. This flaw allows an attacker to introduce malicious XML data into the system, potentially leading to unauthorized data manipulation and service interruptions. Users and administrators are urged to apply security patches and review configurations to mitigate the risks associated with this vulnerability.

Affected Version(s)

Infrastructure Controller Linux 0 to 1.9

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.