CVE-2026-24178Disclosure(apple / linux_kernel)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch apple linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel
  • macos
  • nvflare

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-29); latest day: 3
  • 9 total mentions across 4 days

Affected systems

Products
linux_kernelmacosnvflare

1 version affected across 3 products

Deep dive

Activity timeline9 mentions / 4d
01223Mentions · 2026-04-28: 2Mentions · 2026-04-29: 3Mentions · 2026-05-05: 1Mentions · 2026-05-10: 3Patch / Workaround · 2026-04-29: 3Technical Details · 2026-04-28: 2Technical Details · 2026-04-29: 3Technical Details · 2026-05-10: 204-2804-2905-0505-10
Signal classification3 categories
Disclosure
555.6%
General
333.3%
Patch
111.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-282
Disclosure2
2026-04-293
Disclosure2Patch1
2026-05-051
General1
2026-05-103
Disclosure1General2
Full discourse9 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - NVFlare Dashboard Auth Bypass (CVE-2026-24178) An unauthenticated attacker can bypass authentication in the NVFlare Dashboard via a user-controlled key. This leads to full admin privilege escalation, arbitrary code execution, and total access to sensitive project data. 👉 Upgrade to v2.5.0

    Post summary

    The post announces the critical CVE-2026-24178 authentication bypass in NVFlare Dashboard, detailing its privilege escalation potential and advising users to upgrade to v2.5.0 to mitigate.

    0004081
    237 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    NVIDIA issued an urgent patch for a critical 9.8 CVSS flaw in the FLARE SDK. Stop unauthenticated RCE and data tampering. Upgrade to v2.7.2 immediately. #NVIDIAFLARE #AISecurity #FederatedLearning #InfoSec #CyberSecurity #PatchNow #CVE #Linux #MacOS https://securityonline.info/nvidia-flare-sdk-critical-vulnerability-cve-2026-24178-patch/ https://t.co/tT2avgpibx

    Post summary

    The text announces an urgent update for NVIDIA FLARE SDK CVE-2026-24178 with a 9.8 CVSS score, mitigating unauthenticated RCE and data tampering by upgrading to v2.7.2.

    01011325
    11.5K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.8 CRITICAL · CVE-2026-24178 · 9.8 → 3.1 CVE: CVE-2026-24178 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post lists the CVE identifier CVE-2026-24178 along with its CVSS score and vector, but it contains no information about PoC, exploits, active use, or patch availability.

    1000035
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-24178-nvidia-nvflare #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text merely links to a research page about CVE-2026-24178 and includes generic hashtags, offering no detail on exploitation, mitigation, or vulnerability specifics.

    0000018
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-24178 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may…

    Post summary

    Announcement of CVE‑2026‑24178 for NVIDIA NVFlare Dashboard, classified as critical with a CVSS 9.8 score; no evidence of active exploitation, PoC, or patch availability presented.

    0000040
    197 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-24178: NVIDIA NVFlare Dashboard Authorization Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04fsrfD0

    Post summary

    The article title announces the existence of CVE‑2026‑24178 and suggests discussion of its business impact and response, but does not provide specific technical details, evidence of exploitation, or mitigation steps.

    0000036
    29 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 Critical CVEs Today: IoT & Cloud Stack (CVSS 9.8-9.8) Affected: Milesight AIOT; NVIDIA NVFlare Dashboard; Totolink A8000RU CGI Handler Internet-facing risks dominate, led by IoT devices and cloud platforms; fixes and mitigations below. • CVE-2026-32644 (CVSS 9.8) Milesight AIOT cameras with affected firmware versions use SSL certificates with default private keys. • CVE-2026-24178 (CVSS 9.8) NVIDIA NVFlare Dashboard (unspecified versions) contains unauthenticated authorization bypass via a user-controlled key. • CVE-2026-7202 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setWiFiWpsStart allows remote OS command injection via wscDisabled. • CVE-2026-7203 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setUrlFilterRules allows remote OS command injection via enable parameter. • CVE-2026-7204 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 CGI Handler setPptpServerCfg allows remote OS command injection via enable parameter. 🛠️ Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (process spawning, webshell/file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces several high‑severity CVEs affecting IoT and cloud products, provides technical details, and outlines patches, mitigations, and monitoring steps.

    0000057
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24178 NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass th… https://www.cve.org/CVERecord?id=CVE-2026-24178

    Post summary

    NVIDIA NVFlare Dashboard is vulnerable to an authorization bypass that allows unauthenticated attackers to gain elevated privileges.

    00000104
    57.3K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-24178 NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthentic… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-24178 #NVIDIA #CyberSecurity #InfoSec

    Post summary

    The post announces a critical NVIDIA CVE (CVE-2026-24178) with no patch available, highlighting technical details but lacking any exploit or active usage information.

    0000042
    167 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
OSlinuxlinux_kernel---
Appnvidianvflare---

Explore more