CVE-2026-65093

9.9

NVIDIA · OpenShell

A sandbox escape vulnerability in NVIDIA OpenShell for Linux allows attackers with low privileges to execute arbitrary code, escalate privileges, and disclose sensitive information.

Executive summary

A critical sandbox escape vulnerability in NVIDIA OpenShell allows low-privileged attackers to achieve full system compromise and execute arbitrary code.

Vulnerability

This vulnerability is an uncontrolled search path element (CWE-427) that enables a sandbox escape. It requires an attacker to have low privileges on the system to successfully trigger the flaw.

Business impact

The potential for privilege escalation and arbitrary code execution poses a severe risk to the confidentiality, integrity, and availability of affected systems. Given the CVSS score of 9.9, this vulnerability represents an extreme risk that could allow unauthorized actors to move laterally within the network or exfiltrate sensitive data.

Remediation

Immediate Action: Update NVIDIA OpenShell to the latest available version provided by the vendor.

Proactive Monitoring: Monitor system logs for unauthorized process execution or suspicious attempts to access restricted directories.

Compensating Controls: Implement strict file system permissions and restrict user access levels to minimize the potential impact of a sandbox escape.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for complete system compromise, organizations should prioritize patching NVIDIA OpenShell immediately. If an update is not currently available, ensure that access to the affected software is restricted to only the most trusted users to mitigate the risk of privilege escalation.

More NVIDIA CVEs