Description
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
Published: 2026-08-25
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenShell for Linux contains a sandbox escape vulnerability that can grant an attacker arbitrary code execution beyond the intended confinement. This flaw allows elevation of privileges, data tampering, and exposure of sensitive information, aligning with the Path Manipulation weakness identified as CWE-427.

Affected Systems

The affected product is NVIDIA OpenShell running on Linux systems. The specific version information is not disclosed in the public data, implying that all current releases may remain vulnerable until a vendor update is issued.

Risk and Exploitability

The CVSS score is 9.9, indicating a critical issue. The EPSS score is not available, so the likelihood of exploitation is uncertain; however, the high severity and the potential for code execution and privilege escalation make it a top priority for remediation. The vulnerability is not listed in the CISA KEV catalog, but the impact warrants rapid action.

Generated by OpenCVE AI on August 25, 2026 at 22:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest NVIDIA OpenShell security update or patch for CVE-2026-65093 as soon as it becomes available.
  • Restrict the execution of OpenShell binaries to trusted users or services and limit the use of privileged accounts.
  • Enforce mandatory access controls such as SELinux or AppArmor to contain the OpenShell process and guard against privilege escalation.
  • Configure network policies and firewall rules to limit exposure of any OpenShell‑related services to internal hosts only.

Generated by OpenCVE AI on August 25, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Sandbox Escape Vulnerability in NVIDIA OpenShell Enables Privilege Escalation and Code Execution

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-25T20:15:14.902Z

Reserved: 2026-07-21T17:05:44.174Z

Link: CVE-2026-65093

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:29.300

Modified: 2026-08-25T21:17:29.300

Link: CVE-2026-65093

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:15:04Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element