High‑severity NVIDIA DCGM Exporter flaw (CVE‑2026‑47483) lets unauthenticated attackers crash GPU monitoring
What It Is – A remote‑code‑execution‑adjacent vulnerability in NVIDIA’s Data Center GPU Manager (DCGM) Exporter that allows anyone on the Internet to send crafted HTTP requests and crash the metrics service.
Exploitability – Publicly disclosed, CVSS 8.2 (High). No authentication required; proof‑of‑concept demonstrated by the Lava research team.
Affected Products – NVIDIA DCGM Exporter (versions prior to the July 2026 patch) running on GPU‑focused servers (Blackwell Ultra B300, H200, H100, RTX 4090/5090, etc.).
Why It Matters for Trust & Control Assurance
- Exposed monitoring endpoints bypass identity controls, breaking the “only authorized users may view or affect system metrics” control objective that underpins many frameworks (e.g., NIST CSF Identify & Protect).
- A crash of the exporter can hide performance anomalies, eroding the evidentiary trail needed for audit readiness and continuous compliance reporting.
- The incident highlights the need for continuous verification that critical observability services are hardened, authenticated, and logged.
Recommended Actions
- Inventory all DCGM Exporter instances and verify they are not reachable from the public Internet.
- Apply NVIDIA’s July 2026 security patch to all exporters.
- Enforce authentication (e.g., mTLS, token‑based) on the
/metricsand/debug/pprofendpoints. - Add network‑level allow‑list rules and host‑based firewalls to restrict access to trusted monitoring collectors.
- Integrate exporter health checks into your continuous control‑monitoring platform to generate alerts on unexpected restarts or metric gaps.
Source: Help Net Security – NVIDIA DCGM Exporter vulnerability (CVE‑2026‑47483)