ZeroHour

CVE-2026-65105

moderate

Unauthenticated Access Flaw in NVIDIA NemoClaw Inference Server for Linux

CVSS 3.1
8.1 high
EPSS
<1%p23
Published
()
Modified
AI analysis

NVIDIA NemoClaw for Linux contains a missing-authentication vulnerability (CWE-306) in its inference server setup, allowing the inference service to be reached without any credentials. An attacker needs network reachability to the service — NVIDIA's CVSS vector rates the attack vector as adjacent (AV:A), meaning the same network segment or another routed path to the exposed service — with no privileges or user interaction required. A successful attacker can read information exposed by the service (high confidentiality impact) and disrupt it, causing denial of service (high availability impact), with no integrity impact. Any deployment of NVIDIA NemoClaw's inference server on Linux is potentially affected, though the available data does not specify affected version ranges. No exploitation has been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days (23rd percentile).

What to do: Check NVIDIA's security bulletin for fixed NemoClaw releases and upgrade as soon as a patched version is published, since affected version ranges are not specified in the current data. Until then, restrict access to the inference service to trusted network segments — via firewall rules, segmentation, or an authenticating reverse proxy — because exploitation requires adjacent network reachability. Audit whether the inference service's port is reachable from beyond its intended segment, including from shared networks or routed paths.

Affected
NVIDIA NemoClaw (Linux)
Estimated exposure
moderatelikely on the order of thousands of Linux deployments (rough estimate) — No public install-base or scan counts are available for this product; the estimate is inferred from typical deployment patterns of NVIDIA AI inference tooling in enterprise and research GPU environments rather than measured data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.

Vendors
nvidia
Products
nemoclaw
Weakness
CWE-306
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.