CVE-2025-23260: CWE-266: Incorrect Privilege Assignment in NVIDIA AIS Operator
NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using the ServiceAccount attached to the ClusterRole. A successful exploit of this vulnerability may lead to information disclosure.
AI Analysis
Technical Summary
NVIDIA AIStore's AIS Operator contains a privilege assignment vulnerability (CWE-266) that allows a user with certain access to escalate privileges within a Kubernetes cluster. This occurs because the ServiceAccount is improperly attached to a ClusterRole, enabling elevated access beyond intended permissions. The vulnerability affects all versions prior to 2.3.0 and has a CVSS 3.1 base score of 5.0, indicating medium severity. No patch or official remediation guidance is currently available.
Potential Impact
Successful exploitation can result in elevated Kubernetes cluster access and potential information disclosure. There is no indication of integrity or availability impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict access to the AIS Operator and associated ServiceAccounts to trusted users only. Monitor for updates from NVIDIA regarding patches or configuration changes to address this privilege assignment issue.
CVE-2025-23260: CWE-266: Incorrect Privilege Assignment in NVIDIA AIS Operator
Description
NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using the ServiceAccount attached to the ClusterRole. A successful exploit of this vulnerability may lead to information disclosure.
CVSS v3.1
Score 5.0medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
NVIDIA AIStore's AIS Operator contains a privilege assignment vulnerability (CWE-266) that allows a user with certain access to escalate privileges within a Kubernetes cluster. This occurs because the ServiceAccount is improperly attached to a ClusterRole, enabling elevated access beyond intended permissions. The vulnerability affects all versions prior to 2.3.0 and has a CVSS 3.1 base score of 5.0, indicating medium severity. No patch or official remediation guidance is currently available.
Potential Impact
Successful exploitation can result in elevated Kubernetes cluster access and potential information disclosure. There is no indication of integrity or availability impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict access to the AIS Operator and associated ServiceAccounts to trusted users only. Monitor for updates from NVIDIA regarding patches or configuration changes to address this privilege assignment issue.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- nvidia
- Date Reserved
- 2025-01-14T01:06:22.263Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 685ae55477d44901f08d324f
Added to database: 06/24/2025, 17:50:12 UTC
Last enriched: 05/26/2026, 20:17:48 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 208
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.