GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA NeMo Speech: RCE and privilege escalation in the speech data explorer

CVSS 7.8CVE-2026-24267AI/ML frameworks & servingcurated

Impact

The speech data explorer component executes attacker-controlled data, yielding code execution and escalation of privileges on the host running it, along with information disclosure and data tampering. The explorer is a dataset-inspection tool that people point at corpora they did not produce, which is exactly the trust boundary this breaks: reviewing a tenant's or a third party's dataset hands that dataset's author code on the box. NVIDIA also lists privilege escalation for this id, unlike the other NeMo Speech issues in the same bulletin, so a compromise here can reach beyond the analyst's own account on a shared workstation or utility node.

Who can reach it

Anyone who can place a dataset or manifest that the speech data explorer is then used to inspect. No prior authentication to NeMo; user interaction required, local vector (AV:L/UI:R).

What to do

Update NeMo Speech per NVIDIA security bulletin 2026/5885 and restart the data explorer. The record does not state a fixed version - check the bulletin. Meanwhile do not run the explorer against untrusted datasets on a host with cluster or registry credentials; run it as an unprivileged user in a throwaway container.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.