NvidiaCVE-2026-24185
Nvidia NVOS: privilege escalation
High7.1CVE-2026-24185 · Published Aug 18, 2026 · updated Aug 20, 2026
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| NVOS Product | <= 0.0 to 25.0.2.4438 | No fix yet |
| <= 0.0 to 25.0.2.6077 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-288
More Nvidia advisories
All Nvidia| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 18 | Nvidia Triton Inference Server: improper input validation | High7.5 | No fix yet |
| Aug 18 | Nvidia Triton Inference Server: path traversal | Medium5.5 | No fix yet |
| Aug 18 | Nvidia Triton Inference Server: path traversal | Critical9.8 | No fix yet |
| Aug 18 | Nvidia Triton Inference Server: denial of service | High7.5 | No fix yet |
| Aug 18 | Nvidia Triton Inference Server: path traversal | Medium6.5 | No fix yet |
| Aug 18 | Nvidia Cumulus Linux GA: privilege escalation | High7.8 | No fix yet |