Junglewise Threat Intelligence

CVE-2026-65092: NVIDIA OpenShell Sandbox for Linux path traversal bypass in L7 REST policy

CVE-2026-65092 · Severity: high · CVSS 8.5 · Published 2026-08-25

Technologies: Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA OpenShell Sandbox for Linux is a container and process isolation tool used to restrict application behavior and enforce network policies. A path traversal vulnerability allows an attacker to bypass Layer 7 REST network policies, potentially exposing sensitive data or modifying protected resources within the sandbox.

Technical details

The vulnerability is a path traversal bypass in the L7 REST network policy enforcement mechanism of NVIDIA OpenShell Sandbox for Linux. An attacker can craft malicious path requests to circumvent the REST API policy controls. The attack requires network access to the affected sandbox container and its REST endpoint. Successful exploitation allows information disclosure and data tampering of resources that should be protected by the REST network policy. Patches are expected to be available from NVIDIA.

Affected products

  • NVIDIA OpenShell Sandbox for Linux

Timeline

  • 2026-08-25: disclosed

References

Related threats