Executive brief
NVIDIA NemoClaw is a remote-access tool for Linux systems that enables administrators to manage systems from a distance. A weakness in its authentication mechanism could allow an attacker to bypass security controls and gain unauthorized access to affected systems, potentially leading to theft of sensitive data, system compromise, or malicious code execution.
Technical details
The vulnerability exists in NVIDIA NemoClaw's remote-access helper workflow and allows an attacker to cause weak authentication, bypassing intended access controls. The flaw is network-accessible and does not require prior authentication or special privileges to exploit. A successful attack could lead to code execution, information disclosure, and data tampering on affected Linux systems running NemoClaw. Patches or updates from NVIDIA are expected to address this issue.
Affected products
- NVIDIA NemoClaw <UNKNOWN>
Timeline
- 2026-08-25: disclosed