Junglewise Threat Intelligence

CVE-2026-24212: NVIDIA Isaac Launchable cleartext transmission of sensitive information

CVE-2026-24212 · Severity: high · CVSS 7.5 · Published 2026-05-26

Vendors: Nvidia.

Executive brief

NVIDIA Isaac Launchable for Linux, a tool used for deploying robotics applications, contains a security flaw where sensitive data is sent over the network without encryption. An attacker on the same local network could intercept this information to gain unauthorized access or take control of the system. This could lead to data theft, unauthorized privilege elevation, or the execution of malicious commands on the affected robotics platform.

Technical details

NVIDIA Isaac Launchable for Linux is vulnerable to CWE-319 (Cleartext Transmission of Sensitive Information). The application transmits sensitive data over the network without encryption, which can be intercepted by an attacker with adjacent network access. According to the CVSS vector, the attack complexity is high, suggesting specific conditions or timing may be required to successfully capture the relevant traffic. If exploited, this vulnerability allows for information disclosure, which can be leveraged to achieve remote code execution, escalation of privileges, and data tampering. Users are advised to refer to NVIDIA advisory 5830 for patching information.

Affected products

  • NVIDIA Isaac Launchable Linux versions

Timeline

  • 2026-05-26: disclosed: Initial publication of the CVE record

References