The Information Machine
Concluded·Day 8·first covered 4 Sep 2026·3 sources

Audits find critical cross-tenant RCE flaws across GPU neocloud providers

The gist

Cross-tenant vulnerabilities in GPU cloud infrastructure can expose AI workloads and customer credentials across organizational boundaries. The flaws span multiple providers, pointing to systemic gaps in tenant isolation, patching, and access controls across the neocloud sector.

The full picture

Security researchers at SemiAnalysis and ClusterMax audited multiple GPU-as-a-service neocloud providers and found widespread critical vulnerabilities spanning tenant isolation, container security, and credential exposure. One audited environment ran Docker Engine 29.1.3, within the affected range for CVE-2026-41567, which allows malicious containers to execute arbitrary code as root on the host. Researchers documented a full remote code execution chain via a gem exploit, followed by kernel-level privilege escalation using a technique called 'pte_physroot' and CVE-2026-46300, a Linux kernel vulnerability published May 23. ClusterMax researchers found a cross-tenant RCE at an Asian provider where writing to logs in one tenant allowed reading from another, potentially exposing credentials of OpenRouter inference customers. A Grafana dashboard at one provider used a single OAuth token scoped across all tenants, leaking every tenant's metrics to any querying user. Additional findings include exposed cockpit servers potentially vulnerable to CVE-2026-4631, open BMC controllers, missing InfiniBand keys, broken storage isolation, and single-layer container isolation without VM backing. At least one provider was notified and was working with auditors to verify patches at the time of disclosure.

How it developed
4 September 2026

SemiAnalysis publishes audit findings documenting critical vulnerabilities across neocloud GPU providers.

Sources
The daily email

Want this in your inbox?

I send one email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free