← Terug naar overzicht

NVIDIA NemoClaw for Linux contains a critical vulnerability in its inference server setup that allows remote attackers to access the inference service without authentication. The flaw can be exploited remotely without any credentials, making it particularly dangerous in exposed deployments. A successful exploit may lead to information disclosure, potentially exposing sensitive model data or inference results. The vulnerability also enables denial of service attacks, which could disrupt AI inference workloads. NVIDIA has published a security advisory on their GitHub product-security repository. The vulnerability has been assigned CVE-2026-65105 and is tracked on both NVD and CVE.org. Given the unauthenticated remote access nature, this vulnerability poses a high risk to organizations using NVIDIA NemoClaw in their AI/ML infrastructure.

Affected products

  • NVIDIA NemoClaw for Linux

Related CVE's

  • CVE-2026-65105

Categories

  • Data Breach & Exfiltration
  • Emerging Technologies
  • Identity & Access