← Back to search

CVE-2026-65128

8.8 HIGHpublic exploit available

Published 2026-09-22 · Updated 2026-09-22

AI risk analysis

Summary
This vulnerability in NVIDIA Infrastructure Controller for Linux allows an attacker to inject SQL commands, potentially leading to code execution, data tampering, denial of service, and information disclosure.
Exploitability
Exploitation requires local access and knowledge of the SQL injection vulnerability. Precondition is the presence of unpatched software.
Blast radius
If exploited, the impact could be severe, including unauthorized access, data loss, and system disruption.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 2.590 or later.
rcesql-injectionlinuxnvidiapatch

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.