Executive brief
NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, contains a critical security flaw that allows attackers to bypass authentication. By exploiting this weakness, an unauthorized user could gain full control over the server, potentially leading to the theft of sensitive AI models, data tampering, or a complete shutdown of AI-driven services. This poses a significant risk to business operations and intellectual property stored within the inference environment.
Technical details
NVIDIA Triton Inference Server is vulnerable to an authentication bypass using an alternate path or channel (CWE-288). The vulnerability allows a remote, unauthenticated attacker to bypass security controls and interact with the server's management or inference APIs. According to the CVSS 3.1 vector, the attack is low complexity and requires no user interaction. Successful exploitation can lead to high impacts on confidentiality, integrity, and availability, including potential remote code execution, privilege escalation, and information disclosure. Users are advised to refer to NVIDIA advisory 5828 for specific patching information.
Affected products
- NVIDIA Triton Inference Server
Timeline
- 2026-05-20: disclosed: Initial disclosure by NVIDIA and NVD publication.