Junglewise Threat Intelligence

CVE-2026-65087: NVIDIA NemoClaw insufficiently protected credentials vulnerability

CVE-2026-65087 · Severity: medium · CVSS 5.6 · Published 2026-08-25

Technologies: Nvidia Nemoclaw, Linux Kernel. Vendors: PyPI, Nvidia, Linux.

Executive brief

NVIDIA NemoClaw is a software component used in NVIDIA's AI and machine learning infrastructure. The vulnerability allows attackers to access insufficiently protected credentials, potentially leading to unauthorized access to sensitive systems and data tampering. An attacker exploiting this flaw could gain access to credentials used by the application, compromising data integrity and enabling further attacks on connected systems.

Technical details

NemoClaw contains a vulnerability related to insufficient protection of credentials, classified as a credential management flaw. The root cause involves inadequate encryption, storage, or access controls around sensitive authentication material. The vulnerability is accessible over a network to an unauthenticated attacker, though the exact attack vector and preconditions are not fully detailed in the advisory text. A successful exploit could enable information disclosure of credentials and allow tampering with application data. A patch may be available through NVIDIA security channels.

Affected products

  • NVIDIA NemoClaw

Timeline

  • 2026-08-25: disclosed

References

Related threats