PT-2026-35753 · Unknown · Nvflare Dashboard

Published

2026-04-28

·

Updated

2026-05-10

·

CVE-2026-24178

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NVFlare Dashboard versions prior to 2.5.0
Description A flaw in the user management and authentication system allows an unauthenticated attacker to bypass authorization using a user-controlled key. This can result in privilege escalation to full administrator levels, arbitrary code execution, data tampering, information disclosure, and denial of service, granting total access to sensitive project data.
Recommendations Update to version 2.5.0.

Fix

LPE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24178
GHSA-JQP3-QRGH-4846
PYSEC-2026-100

Affected Products

Nvflare Dashboard