External risk intelligence

NVIDIA Infrastructure Controller Hard-Coded Credentials Vulnerability Leads to Privilege Escalation and Data Tampering

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-65113

The NVIDIA Infrastructure Controller is a specialized component used within internal data center or server infrastructure management. While it operates on a network, it is typically deployed within isolated management networks or private fabric configurations rather than being directly exposed to the public internet in common deployments.

Information Disclosure

Nvidia Infra Controller

before 2.0.0

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in NVIDIA's Infrastructure Controller for Linux, specifically related to hard-coded credentials. An attacker could potentially exploit this to gain elevated privileges, alter data, disrupt services, or access sensitive information, impacting the integrity and availability of systems managed by this controller.

  • Hard-coded credentials allow unauthorized access.
  • Critical systems could face compromise and disruption.
  • Verify if this controller is in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit a vulnerability in NVIDIA Infrastructure Controller for Linux by leveraging hard-coded credentials. This could allow them to gain elevated privileges, alter data, disrupt services, or steal sensitive information. The attacker starts with no prior access and needs to reach the controller over the network.

  • No prior access needed.
  • Uses hard-coded credentials.
  • Leads to significant system compromise.

Live Threat

Current exploitation, exposure, and threat context

An attacker could exploit a vulnerability in NVIDIA Infrastructure Controller for Linux to use hard-coded credentials. When successfully exploited, this could lead to unauthorized privilege escalation, modification of data, service disruption, or unauthorized access to information.

  • System credentials and access controls.
  • Network-based exploitation of the controller.
  • Potential for unauthorized system access.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this critical vulnerability, infrastructure and platform teams are likely responsible for managing the NVIDIA Infrastructure Controller for Linux. The immediate first step is to pinpoint all instances of this controller within your environment, confirm its network exposure and business criticality, and identify the specific asset owner. Subsequently, a risk-based remediation plan should be developed and executed.

  • Infrastructure and platform teams own remediation.
  • Verify controller existence and criticality first.
  • Plan and coordinate risk-based updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the NVIDIA Infrastructure Controller?

The NVIDIA Infrastructure Controller is a specialized software component designed for Linux environments. It is primarily used by administrators to manage and orchestrate server or data center hardware functions, ensuring that complex infrastructure components communicate and operate efficiently within the system.

What does CWE-798 mean for CVE-2026-65113?

This vulnerability is classified as CWE-798, which refers to the use of hard-coded credentials. In this specific case, the software contains fixed, built-in login information that cannot be changed by the user. If an attacker discovers these hidden credentials, they can bypass standard authentication mechanisms to gain unauthorized access to the controller.

How does an attacker trigger this vulnerability?

An attacker triggers this bug by reaching the controller over the network and providing the hard-coded credentials to authenticate. Note that this flaw is not triggered by user interaction or typical application usage; it stems directly from the presence of the fixed credentials within the software's code itself.

Do I need to worry if my controller is internal?

Halo Surface Signal indicates that this controller is typically used in isolated management networks or private fabrics. While the vulnerability allows network-based exploitation, systems kept off the public internet are less likely to face immediate external threats compared to those directly reachable from the outside.

What are the first steps to address CVE-2026-65113?

Start by identifying all instances of the NVIDIA Infrastructure Controller running in your environment. Confirm which systems are currently using versions prior to 2.0.0. Once located, coordinate with your infrastructure and platform teams to evaluate the business criticality of these assets and prioritize a plan to apply the necessary updates.

References