NVIDIA AIStore - AuthN: A flaw in the AIStore authentication component reaches privilege escalation, information
CVE-2025-33186NVIDIA / GPU stackcurated
Impact
A flaw in the AIStore authentication component reaches privilege escalation, information disclosure and data tampering - effectively an authentication bypass in front of your training data store. Scored 8.8 network with no privileges required.
Who can reach it
Network, unauthenticated, one user-interaction step. Anyone with a route to AIStore's AuthN service.
What to do
Upgrade AIStore per bulletin 5724 as a priority and rotate AuthN tokens afterwards - the patch does not invalidate credentials an attacker may already hold. Cost: rolling control-plane restart.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.