CVE-2026-65087
Received Received - Intake

Insufficiently Protected Credentials in NVIDIA NemoClaw

Vulnerability report for CVE-2026-65087, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: NVIDIA Corporation

Description

NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nvidia nemoclaw *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NVIDIA NemoClaw has a vulnerability where attackers could access insufficiently protected credentials. This might allow them to steal information or alter data.

Impact Analysis

An attacker could exploit this to disclose sensitive information or tamper with data, potentially leading to unauthorized access or data corruption.

Mitigation Strategies

Update NVIDIA NemoClaw to the latest version to address insufficiently protected credentials. Ensure proper access controls and encryption for sensitive data to prevent information disclosure and data tampering.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65087. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart