Description
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-07-01
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in NVIDIA AIStore framework allows an attacker to bypass authentication controls, permitting them to perform actions without valid credentials. This can lead to denial of service, privilege escalation, information disclosure, and data tampering, impacting confidentiality, integrity, and availability of the system.

Affected Systems

NVIDIA AIStore framework is the affected product; specific versions are not listed in the data provided.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV. Based on the description, the attack vector likely involves remote exploitation through the AIStore interface and requires no authentication, making exploitation highly feasible.

Generated by OpenCVE AI on July 2, 2026 at 05:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA AIStore framework patch or upgrade to a non-affected release
  • Limit network access to the AIStore service to trusted hosts or blocks unauthorized IP ranges
  • Enable and review audit logs for anomalous authentication attempts and unauthorized changes

Generated by OpenCVE AI on July 2, 2026 at 05:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA AIStore Framework

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-01T15:56:06.586Z

Reserved: 2026-01-21T19:09:49.054Z

Link: CVE-2026-24270

cve-icon Vulnrichment

Updated: 2026-07-01T15:56:02.703Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-02T05:15:07Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing