CVE-2026-65111: Command Injection
Published Sep 22, 2026
·Updated
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Affected Software
1 affected component
Nvidia NeMo Speech
Event History
Sep 22, 2026
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation requires local access and low privileges. No user interaction is required.
2
What could a successful exploit allow?
A successful exploit could result in code execution, information disclosure, and data tampering. The CVSS vector indicates high impacts to confidentiality, integrity, and availability.
3
Is this exposed over the network by the stated CVSS assessment?
No. The provided CVSS vector has an attack vector of local (AV:L), so the assessment does not describe network-based exploitation.