Description
NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

NVIDIA NeMo Speech contains a flaw in its speech data explorer component that permits an attacker to create malicious data files. Loading such data can trigger remote code execution. The exploitation may lead to privilege escalation, data disclosure, and tampering.

Affected Systems

The vulnerability is active in all platforms that ship the current NVIDIA NeMo Speech distribution. The vendor has not published specific version or build numbers that exclude the flaw, so any installation of NeMo Speech that includes the data explorer feature is impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score is not available, so the probability of exploitation remains uncertain. The flaw allows remote execution via crafted data. The vulnerability is not listed in the CISA KEV catalog, but that does not preclude active exploitation. Based on the description, it is inferred that attackers only need to supply a malicious data file to the explorer to trigger code execution.

Generated by OpenCVE AI on September 22, 2026 at 16:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or update NeMo Speech to a version that removes the vulnerable data explorer component.
  • If a patch is unavailable, disable or remove the speech data explorer feature from the installation so that untrusted input cannot be processed.
  • Configure file‑system permissions to restrict non‑trusted users or systems from writing or modifying data within the explorer’s input directory.
  • Monitor system logs for anomalies such as unexpected process creation or execution of binary code that correlates with the data explorer module.

Generated by OpenCVE AI on September 22, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nemo Speech
Vendors & Products Nvidia
Nvidia nemo Speech

Tue, 22 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Malicious Speech Data Exploit in NVIDIA NeMo Speech Enables Remote Code Execution

Tue, 22 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Nvidia Nemo Speech
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-22T15:30:41.207Z

Reserved: 2026-01-21T19:09:49.054Z

Link: CVE-2026-24267

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T15:17:10.157

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-24267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:15:02Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data