Missing Auth. in NVIDIA GPU Display Driver Kernel Module Data Disclosure
CVE-2026-47580 Published on September 30, 2026
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause a missing authorization issue. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
Vulnerability Analysis
CVE-2026-47580 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and no impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-47580 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-47580
stack.watch emails you whenever new vulnerabilities are published in NVIDIA Geforce or NVIDIA Tesla. Just hit a watch button to start following.
Affected Versions
NVIDIA GeForce:- Version All driver versions prior to 610.60 is affected.
- Version All driver versions prior to 610.88 is affected.
- Version All driver versions prior to 616.56 is affected.
- Version All driver versions prior to 616.92 is affected.
- Version All driver versions prior to 582.78 Only GPUs based on the NVIDIA Maxwell, Volta, and Pascal GPU architectures are affected. is affected.
- Version All driver versions prior to 582.78 is affected.
- Version All driver versions prior to 596.86 is affected.
- Version All driver versions prior to 596.86 is affected.
- Version All driver versions prior to 596.86 is affected.
- Version All driver versions prior to 616.92 is affected.
- Version All driver versions prior to 610.88 is affected.