Junglewise Threat Intelligence

CVE-2026-65086: NVIDIA OpenShell for Linux command injection in sandbox exec handler

CVE-2026-65086 · Severity: medium · CVSS 6.8 · Published 2026-08-25

Technologies: Linux Kernel, Nvidia OpenShell for Linux. Vendors: Linux, Nvidia.

Executive brief

NVIDIA OpenShell for Linux is a system utility that manages command execution in restricted environments. A flaw in its sandbox execution handler allows attackers to inject arbitrary operating system commands, potentially leading to unauthorized code execution, theft of sensitive information, and unauthorized modification of system data.

Technical details

The vulnerability is a command injection flaw in OpenShell for Linux's sandbox exec handler. An attacker can inject OS commands through improperly sanitized input, allowing arbitrary code execution with the privileges of the OpenShell process. The attack does not appear to require authentication or user interaction based on the reported severity. A successful exploit could result in code execution, information disclosure, and data tampering. Patches or mitigation guidance is expected to be available from NVIDIA.

Affected products

  • NVIDIA OpenShell for Linux <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats