Executive brief
NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, contains a security flaw that allows unauthorized users to bypass authentication. If exploited, an attacker could gain unauthorized access to the system, potentially leading to the theft of sensitive data, disruption of AI services, or unauthorized administrative control. This poses a significant risk to organizations relying on the server for critical machine learning operations.
Technical details
NVIDIA Triton Inference Server is vulnerable to an authentication bypass (CWE-288) via an alternate path or channel. The vulnerability allows a remote, unauthenticated attacker to bypass security controls over the network without any user interaction. Successful exploitation could grant the attacker elevated privileges, the ability to cause a denial of service (DoS) condition, or unauthorized access to sensitive information stored or processed by the inference server. The issue is tracked as CVE-2026-24206 with a CVSS base score of 7.3.
Affected products
- NVIDIA Triton Inference Server
Timeline
- 2026-05-20: disclosed: Initial publication of the CVE record.
- 2026-05-20: advisory: NVIDIA released security bulletin 5828.