Description
NVIDIA NemoClaw contains a vulnerability where an attacker could cause
insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.
Published: 2026-08-25
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure and Data Tampering
Action: Apply Patch
AI Analysis

Impact

NVIDIA’s NemoClaw subsystem contains a flaw that allows credentials to be insufficiently protected. A successful exploitation of this vulnerability would enable an attacker to read confidential data and alter stored information. The weakness is identified as CWE‑522, indicating that sensitive credentials are not kept secure, and the impact is limited to the integrity and confidentiality of data handled by the affected component.

Affected Systems

The vulnerability affects NVIDIA NemoClaw devices. No specific version numbers are supplied in the public data, so all existing installations of NemoClaw should be treated as potentially impacted until a vendor update is confirmed.

Risk and Exploitability

The CVSS score of 5.6 reflects moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not yet been observed. The likely attack vector is not explicitly stated in the advisory; based on the description, it is inferred that an attacker could manipulate credentials through local or remote interfaces that interact with NemoClaw, but no concrete method is detailed.

Generated by OpenCVE AI on August 25, 2026 at 21:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check NVIDIA’s product security portal or official website for an update or patch addressing the credential protection flaw, and apply it as early as possible.
  • If a patch is not yet available, change or revoke all administrator credentials on NemoClaw devices to eliminate exposure to the identified weak credential storage.
  • Enable network segmentation or firewall rules to restrict external access to NemoClaw management interfaces, thereby reducing the attack surface until a fix is applied.

Generated by OpenCVE AI on August 25, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:a:nvidia:nemoclaw:0.0.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nemoclaw
Vendors & Products Nvidia
Nvidia nemoclaw

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

Linux Linux Kernel
Nvidia Nemoclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-26T17:52:21.963Z

Reserved: 2026-07-21T17:05:36.472Z

Link: CVE-2026-65087

cve-icon Vulnrichment

Updated: 2026-08-26T17:50:58.449Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:28.553

Modified: 2026-09-01T16:38:42.390

Link: CVE-2026-65087

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:00:13Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials