CVE-2026-24178
published 2026-04-28CVE-2026-24178: NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization…
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.57%
43.5th percentile
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | flare_sdk | — | — |
| nvidia | nvflare | < 2.7.2 | 2.7.2 |
| nvidia | nvflare | >= 0 < 2.7.2 | 2.7.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
NVIDIA NVFlare Dashboard: Authorization bypass through user-controlled key via user management and authentication system
ghsa·2026-04-28
CVE-2026-24178 [CRITICAL] CWE-639 NVIDIA NVFlare Dashboard: Authorization bypass through user-controlled key via user management and authentication system
NVIDIA NVFlare Dashboard: Authorization bypass through user-controlled key via user management and authentication system
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.
GHSA
GHSA-jqp3-qrgh-4846: NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authori
ghsa_unreviewed·2026-04-28
CVE-2026-24178 [CRITICAL] CWE-639 GHSA-jqp3-qrgh-4846: NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authori
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.
VulDB
NVIDIA FLARE SDK NVFlare Dashboard authorization
vuldb·2026-04-28·CVSS 9.8
CVE-2026-24178 [CRITICAL] NVIDIA FLARE SDK NVFlare Dashboard authorization
A vulnerability has been found in NVIDIA FLARE SDK and classified as very critical. This affects an unknown part of the component NVFlare Dashboard. The manipulation leads to authorization bypass.
This vulnerability is traded as CVE-2026-24178. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-28
Published