Executive brief
NVIDIA AIStore, a framework used for high-speed data storage and retrieval in AI applications, contains a critical security flaw that allows unauthorized individuals to bypass security checks. This could allow an attacker to gain full control over the system, leading to the theft of sensitive data, disruption of AI operations, or unauthorized modification of stored information. The vulnerability is particularly severe because it can be exploited over the network without needing any existing user credentials.
Technical details
A critical authentication bypass vulnerability (CWE-290) exists in the NVIDIA AIStore framework versions 0 through 4.4. The flaw is rooted in an authentication bypass by spoofing, allowing a remote, unauthenticated attacker to gain unauthorized access to the system. With a CVSS score of 9.8, the attack vector is network-based with low complexity and requires no user interaction. Successful exploitation can result in a total loss of confidentiality, integrity, and availability, including full administrative privilege escalation and data tampering. Users are advised to refer to the NVIDIA June 2026 security bulletin for patching information.
Affected products
- NVIDIA AIStore framework 0 - 4.4
Timeline
- 2026-07-01: advisory: NVIDIA published the security bulletin and CVE details.
- 2026-07-01: disclosed