Description
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-07-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in NVIDIA AIStore framework permits an attacker to bypass authentication controls, enabling actions without valid credentials. The resulting impact can include denial of service, privilege escalation, information disclosure, and data tampering. The weakness is identified as authorization failure (CWE-290).

Affected Systems

The NVIDIA AIStore framework is the affected product. No specific affected versions are listed in the CVE data, so all installations of this framework are potentially vulnerable unless a later release has mitigated the issue.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.8, indicating critical severity. Its EPSS score is less than 1 %, indicating a very low but non‑zero exploitation probability, and it is not included in the CISA KEV catalog. The likely attack vector is remote exploitation through the AIStore interface, inferred because the flaw allows actions without authentication, but this inference is made in the absence of explicit vector data in the CVE description.

Generated by OpenCVE AI on July 21, 2026 at 14:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent NVIDIA AIStore framework release that contains the fix, as listed on NVIDIA’s product‑security page
  • Restrict network access to the AIStore service to trusted hosts or IP ranges
  • Enable and monitor audit logs for anomalous authentication attempts and unauthorized changes

Generated by OpenCVE AI on July 21, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Fri, 17 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Thu, 16 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Tue, 14 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Tue, 14 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Enabling Privilege Escalation and Data Tampering

Sun, 12 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Enabling Privilege Escalation and Data Tampering

Sat, 11 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Fri, 10 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Fri, 10 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework Leading to Privilege Escalation and Data Compromise

Thu, 09 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework Leading to Privilege Escalation and Data Compromise

Wed, 08 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework Leading to Privilege Escalation and Data Compromise

Tue, 07 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework Leading to Privilege Escalation and Data Compromise

Mon, 06 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Sun, 05 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Sun, 05 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework Enabling Privilege Escalation and Data Tampering

Sat, 04 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework Enabling Privilege Escalation and Data Tampering

Sat, 04 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Fri, 03 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Thu, 02 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Thu, 02 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-01T15:56:06.586Z

Reserved: 2026-01-21T19:09:49.054Z

Link: CVE-2026-24270

cve-icon Vulnrichment

Updated: 2026-07-01T15:56:02.703Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:15:04Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing