CVE-2026-65083

9.9

NVIDIA · OpenShell

NVIDIA OpenShell for Linux contains a sandbox provisioning vulnerability where an incomplete list of disallowed inputs allows for potential code execution and privilege escalation.

Executive summary

A critical sandbox escape vulnerability in NVIDIA OpenShell allows authenticated attackers to perform unauthorized actions, including code execution and privilege escalation.

Vulnerability

This vulnerability involves an incomplete list of disallowed inputs (CWE-184) within the sandbox provisioning API. While the CVSS score is 9.9, note that the attack requires authenticated access (PR:L), yet the resulting impact on the system is critical due to the sandbox escape capability.

Business impact

The ability to bypass sandbox restrictions allows an attacker to move from a restricted environment to the underlying host system. This level of access grants the attacker full control over the affected machine, potentially leading to widespread data theft, total system compromise, and the disruption of critical business operations.

Remediation

Immediate Action: Update NVIDIA OpenShell to the latest version as specified in the vendor security advisory.

Proactive Monitoring: Review access logs for anomalous API calls or unauthorized attempts to access restricted system resources from within the sandbox environment.

Compensating Controls: Restrict access to the OpenShell API to only essential users and ensure the host environment is hardened against lateral movement.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for privilege escalation and sandbox escape, this vulnerability must be treated with extreme urgency. Organizations must apply the vendor-provided security updates to all NVIDIA OpenShell installations to maintain the integrity of their security boundaries.

More NVIDIA CVEs