CVE-2026-65105
Analyzed Analyzed - Analysis Complete

NemoClaw Linux Inference Server Authentication Bypass

Vulnerability report for CVE-2026-65105, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-09-01

Assigner: NVIDIA Corporation

Description

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-09-01
Generated
2026-09-15
AI Q&A
2026-08-26
EPSS Evaluated
2026-09-13
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nvidia nemoclaw to 0.0.25 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NVIDIA NemoClaw for Linux has a flaw in its inference server setup that allows remote attackers to access the service without authentication. This could lead to unauthorized information disclosure and denial of service.

Detection Guidance

To detect this vulnerability, scan your network for open ports associated with NVIDIA NemoClaw's inference service. Use commands like 'nmap -p <port> <target_IP>' to check for exposed services. Verify if the service allows unauthenticated access by attempting to connect without credentials.

Impact Analysis

An attacker could exploit this to steal sensitive data or disrupt services relying on NemoClaw. Systems using the vulnerable setup may face unauthorized access, data leaks, or service outages.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized data access or disclosure. Organizations may face legal penalties, fines, or reputational damage if exploited.

Mitigation Strategies

Immediately restrict access to the inference service by enabling authentication and configuring firewalls to block unauthorized connections. Update NVIDIA NemoClaw to the latest patched version if available. Monitor network traffic for suspicious activity targeting the inference service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65105. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart