CVE-2026-24212
NVIDIA Isaac Launchable Cleartext Transmission Vulnerability
Publication date: 2026-05-26
Last updated on: 2026-05-26
Assigner: NVIDIA Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nvidia | isaac_launchable | *-* |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-319 | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability involves the transmission of sensitive information in clear text, which can lead to information disclosure and data tampering.
Such exposure of sensitive data could potentially violate data protection regulations like GDPR and HIPAA, which require the protection of personal and sensitive information during transmission.
However, the provided context and resources do not explicitly discuss the impact of this vulnerability on compliance with these or other common standards and regulations.
Can you explain this vulnerability to me?
NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text.
This means that data that should be protected can be intercepted and read by unauthorized parties.
Exploiting this vulnerability could allow attackers to execute code, escalate privileges, disclose information, or tamper with data on the affected system.
How can this vulnerability impact me? :
If exploited, this vulnerability can have serious impacts including:
- Code execution by attackers, potentially allowing them to run malicious software.
- Escalation of privileges, meaning attackers could gain higher access rights than intended.
- Disclosure of sensitive information that is transmitted in clear text.
- Tampering with data, which could compromise data integrity.