Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-65098: NVIDIA NemoClaw Linux remote helper can be bypassed
CVE-2026-65098 · published 9 days ago
Summary
The remote-access component of NVIDIA NemoClaw on Linux can be tricked into weak authentication, allowing an attacker to run code, view sensitive information, or alter data. This risk affects any system using NemoClaw’s remote helper feature. Apply the vendor’s update or disable the remote helper until it is patched.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| nvidia | nemoclaw |
<= 0.0.4 cpe:2.3:a:nvidia:nemoclaw:*:*:*:*:*:*:*:* |
Original advisory text
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to ...
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Severity
9.8
Critical
CVSS 3.1: 8.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-1390Weak Authentication
Timeline
Published25 Aug 2026
Updated2 Sep 2026
First seen26 Aug 2026
Sources
CVE-2026-65098 · NVD
Monitor software like this
Free during beta