CVE Vulnerabilities

CVE-2025-33179

Incorrect Privilege Assignment

Published: Feb 24, 2026 | Modified: Feb 27, 2026
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successful exploit of this vulnerability might lead to escalation of privileges.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Cumulus_linuxNvidia*5.14.0 (excluding)
Cumulus_linuxNvidia5.9.0 (including)5.9.4 (excluding)
Cumulus_linuxNvidia5.11.0 (including)5.11.4 (excluding)

Potential Mitigations

References