PT-2026-35753 · Unknown · Nvflare Dashboard
Published
2026-04-28
·
Updated
2026-05-10
·
CVE-2026-24178
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NVFlare Dashboard versions prior to 2.5.0
Description
A flaw in the user management and authentication system allows an unauthenticated attacker to bypass authorization using a user-controlled key. This can result in privilege escalation to full administrator levels, arbitrary code execution, data tampering, information disclosure, and denial of service, granting total access to sensitive project data.
Recommendations
Update to version 2.5.0.
Fix
LPE
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nvflare Dashboard