NVIDIA Isaac Launchable: Execution with unnecessary privileges lets an unauthenticated network attacker reach code
CVSS 9.8CVE-2025-33223NVIDIA / GPU stackcurated
Impact
Execution with unnecessary privileges lets an unauthenticated network attacker reach code execution, privilege escalation, information disclosure and data tampering. Scored 9.8.
Who can reach it
Network, unauthenticated, no user interaction.
What to do
Update to the fixed release per bulletin 5749 and redeploy. Cost: redeploy only, but review what privileges the workload actually needs - the underlying pattern is over-privileged execution, which recurs.
References
Related entries
- NVIDIA Isaac Launchable: A second over-privileged execution path with the same unauthenticated network reach and 9.8CVE-2025-33224 · NVIDIA Isaac LaunchableCritical
- NVIDIA Isaac Launchable: Hard-coded credentials in Isaac Launchable give an unauthenticated network attacker codeCVE-2025-33222 · NVIDIA Isaac LaunchableCritical
- NVIDIA FLARE SDK: Unauthenticated remote code executionCVE-2026-24178 · NVIDIA FLARE SDKCritical
- Triton Inference Server: Missing authenticationCVE-2026-24207 · Triton Inference ServerCritical
- NVIDIA Dynamo: Unauthenticated remote code executionCVE-2026-24254 · NVIDIA DynamoCritical
- NVIDIA AIStore: Missing authentication on API endpointsCVE-2026-24270 · NVIDIA AIStoreCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.