Base Command Manager (CMDaemon): Unauthenticated RCE on the cluster manager
Impact
Unauthenticated RCE on the cluster manager -> full cluster takeover
Who can reach it
Network-adjacent unauthenticated attacker reaching CMDaemon
What to do
Emergency: patch Base Command Manager, restrict CMDaemon to the mgmt network, audit for compromise; cluster-wide credential rotation
Fleet impact
How widespread
Common - Base Command / Bright Cluster Manager is the control plane on many enterprise and neocloud GPU clusters
Cost to remediate
daemon-restart of the cluster control plane, which is itself a scheduling outage for the whole cluster
Why it hits the whole fleet
Missing authentication in CMDaemon, remotely exploitable with no user interaction or privileges: compromising the cluster manager means owning provisioning for every node in the cluster at once
References
Related entries
- NVIDIA Isaac Launchable: Hard-coded credentials in Isaac Launchable give an unauthenticated network attacker codeCVE-2025-33222 · NVIDIA Isaac LaunchableCritical
- NVIDIA Isaac Launchable: Execution with unnecessary privileges lets an unauthenticated network attacker reach codeCVE-2025-33223 · NVIDIA Isaac LaunchableCritical
- NVIDIA Isaac Launchable: A second over-privileged execution path with the same unauthenticated network reach and 9.8CVE-2025-33224 · NVIDIA Isaac LaunchableCritical
- NVIDIA FLARE SDK: Unauthenticated remote code executionCVE-2026-24178 · NVIDIA FLARE SDKCritical
- Triton Inference Server: Missing authenticationCVE-2026-24207 · Triton Inference ServerCritical
- NVIDIA Dynamo: Unauthenticated remote code executionCVE-2026-24254 · NVIDIA DynamoCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.