Description
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Published: 2026-08-25
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the remote‑access helper workflow of NVIDIA NemoClaw for Linux. An attacker who can interact with the helper could weaken its authentication process, allowing the attacker to execute arbitrary code, read sensitive data, or alter system data. This weakness is classified as CWE‑1390, indicating improper handling of authentication protocols.

Affected Systems

NVIDIA NemoClaw for Linux is affected. No specific version numbers are listed in the advisory.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1, indicating high severity. The EPSS score is not available, so the overall exploitation probability is unclear, but the description implies that the remote‑access helper is reachable over a network interface, so the likely attack vector is remote. The vulnerability is not currently listed in CISA KEV, suggesting no known widespread exploitation yet. Immediate remediation is recommended to mitigate potential code execution, data disclosure, or tampering.

Generated by OpenCVE AI on August 25, 2026 at 22:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official NVIDIA patch for NemoClaw after checking vendor advisories.
  • Disable or restrict the remote‑access helper workflow if not needed, and enforce strong authentication mechanisms.
  • Monitor system logs for unauthorized authentication attempts and conduct regular security audits.

Generated by OpenCVE AI on August 25, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:a:nvidia:nemoclaw:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Remote-Access Helper Authentication Bypass in NVIDIA NemoClaw

Tue, 25 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nemoclaw
Vendors & Products Nvidia
Nvidia nemoclaw

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Weaknesses CWE-1390
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Linux Linux Kernel
Nvidia Nemoclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-26T14:41:38.252Z

Reserved: 2026-07-21T17:05:44.174Z

Link: CVE-2026-65098

cve-icon Vulnrichment

Updated: 2026-08-26T14:41:33.490Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:29.687

Modified: 2026-09-01T18:47:46.200

Link: CVE-2026-65098

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:15:04Z

Weaknesses