NVIDIA Patches 14 Vulnerabilities in Linux Infrastructure Controller, Including Critical Hardcoded Credentials Flaw
NVIDIA has released security updates for its Infrastructure Controller for Linux, addressing 14 vulnerabilities, including a critical flaw (CVE-2026-65113) with a CVSS score of 9.8 that allows remote attackers elevated privileges.

NVIDIA has issued a critical security update for its Infrastructure Controller software designed for Linux environments, patching a total of 14 vulnerabilities. These flaws could potentially allow attackers to access sensitive system information, execute arbitrary code, modify data, or disrupt operations. The updates are detailed in NVIDIA’s September 2026 Infrastructure Controller security bulletin and address issues affecting versions 0 through 1.9 of the software.
The most severe vulnerability, identified as CVE-2026-65113, carries a CVSS score of 9.8 and is classified as critical. This flaw stems from the use of hard-coded credentials within the software, enabling remote, unauthenticated attackers to gain elevated privileges. Successful exploitation could lead to data manipulation, denial-of-service conditions, or the disclosure of sensitive information.
Another high-severity vulnerability, CVE-2026-65128, is an SQL injection flaw with a CVSS score of 8.8. This vulnerability requires low privileges and no user interaction to exploit, potentially allowing for code execution, data tampering, service disruption, and information disclosure.
Several other high-severity vulnerabilities were also addressed, including missing or improper authentication mechanisms (CVE-2026-65114, CVE-2026-65121), OS command injection (CVE-2026-65130), and improper certificate validation (CVE-2026-65118). These flaws range in severity from CVSS 8.3 down to 8.0 and could lead to data tampering, privilege escalation, information exposure, and in the case of command injection, a complete compromise of confidentiality, integrity, and availability.
The update also includes fixes for medium-severity vulnerabilities such as uncontrolled resource consumption (CVE-2026-65115, CVE-2026-65112), external control of file names or paths (CVE-2026-65125), XML injection (CVE-2026-65124), hard-coded password usage (CVE-2026-65117), improper certificate validation (CVE-2026-65129), and improper enforcement of behavioral workflows (CVE-2026-65126). Additionally, CVE-2026-65127 addresses the exposure of sensitive system information through uncleared debug information, carrying a CVSS score of 4.1.
NVIDIA strongly recommends that all users of Infrastructure Controller for Linux update their software to version 2.0 or later to mitigate these risks. Organizations should also conduct a thorough review of their deployed systems, including exposed services, access controls, credentials, logs, and network segmentation, to ensure comprehensive security.
The Infrastructure Controller plays a role in managing NVIDIA infrastructure components, making timely patching crucial for environments that rely on this software. While NVIDIA provides severity ratings, security teams are advised to assess the specific risk to their installations based on their unique configurations, user privileges, network accessibility, and the operational importance of the affected controller.
This comprehensive patch addresses a wide array of security weaknesses, highlighting the ongoing need for vigilance in securing complex infrastructure software. The variety of vulnerabilities, from critical hard-coded credentials to less severe information disclosure issues, underscores the importance of regular security audits and prompt application of vendor-supplied updates.