Junglewise Threat Intelligence

CVE-2026-65105: NVIDIA NemoClaw inference server authentication bypass

CVE-2026-65105 · Severity: high · CVSS 8.1 · Published 2026-08-25

Technologies: Nvidia Nemoclaw, Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA NemoClaw for Linux is a machine learning inference platform used to deploy AI models. The inference server can be accessed by remote attackers without authentication, allowing them to extract sensitive model data, inference inputs/outputs, and disrupt service availability.

Technical details

NVIDIA NemoClaw for Linux contains an authentication bypass vulnerability in its inference server setup. The vulnerability allows remote attackers to access the inference service without credentials, bypassing the intended authentication mechanism. Successful exploitation can lead to information disclosure (exposure of models, inference data, and system information) and denial of service through resource exhaustion or service disruption. The vulnerability is network-reachable and requires no prior authentication or user interaction. Patches are expected from NVIDIA.

Affected products

  • NVIDIA NemoClaw <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats