CRITICAL 9.8 PyPI
NVIDIA NVFlare Dashboard: Authorization bypass through user-controlled key via user management and authentication system
GHSA-jqp3-qrgh-4846 · CVE-2026-24178 · PYSEC-2026-100
Published · Modified
Description
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-24178
- PACKAGE https://github.com/NVIDIA/NVFlare
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/nvflare/PYSEC-2026-100.yaml
- WEB https://nvidia.custhelp.com/app/answers/detail/a_id/5819
- WEB https://www.cve.org/CVERecord?id=CVE-2026-24178
Ready to move
Start Securing
Free, no credit card | First findings in minutes