NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 28 Apr 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Authorization Bypass via User‑Controlled Key in NVIDIA FLARE Dashboard |
Tue, 28 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service. | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: nvidia
Published:
Updated: 2026-04-28T17:44:51.538Z
Reserved: 2026-01-21T19:09:31.778Z
Link: CVE-2026-24178
No data.
Status : Awaiting Analysis
Published: 2026-04-28T19:36:45.127
Modified: 2026-04-28T20:10:42.070
Link: CVE-2026-24178
No data.
OpenCVE Enrichment
Updated: 2026-04-28T23:15:43Z
Weaknesses