NVIDIA Isaac Launchable: Hard-coded credentials in Isaac Launchable give an unauthenticated network attacker code
Impact
Hard-coded credentials in Isaac Launchable give an unauthenticated network attacker code execution and privilege escalation - scored 9.8. Hard-coded credentials are unpatchable by configuration: the fix has to be a new build, and any deployment still running the old artifact stays exploitable regardless of what you change around it.
Who can reach it
Network, unauthenticated, no user interaction. The credentials are in the artifact, so anyone with the artifact has them.
What to do
Update to the fixed Isaac Launchable release per bulletin 5749 and rotate anything the embedded credential could reach. Cost: redeploy. Critically, patching alone is insufficient - assume the credential is public and revoke it.
References
Related entries
- NVIDIA Isaac Launchable: Execution with unnecessary privileges lets an unauthenticated network attacker reach codeCVE-2025-33223 · NVIDIA Isaac LaunchableCritical
- NVIDIA Isaac Launchable: A second over-privileged execution path with the same unauthenticated network reach and 9.8CVE-2025-33224 · NVIDIA Isaac LaunchableCritical
- NVIDIA FLARE SDK: Unauthenticated remote code executionCVE-2026-24178 · NVIDIA FLARE SDKCritical
- Triton Inference Server: Missing authenticationCVE-2026-24207 · Triton Inference ServerCritical
- NVIDIA Dynamo: Unauthenticated remote code executionCVE-2026-24254 · NVIDIA DynamoCritical
- NVIDIA AIStore: Missing authentication on API endpointsCVE-2026-24270 · NVIDIA AIStoreCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.