Junglewise Threat Intelligence

CVE-2026-47481: NVIDIA Triton Inference Server authentication bypass via alternate path

CVE-2026-47481 · Severity: medium · CVSS 6.5 · Published 2026-07-14

Technologies: Nvidia Triton Inference Server. Vendors: Nvidia.

Executive brief

NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, contains a security flaw that allows unauthorized users to bypass authentication. By accessing the system through an unintended path, an attacker could potentially view sensitive data, modify information, or gain higher levels of access. This could lead to the compromise of proprietary AI models or the integrity of the data they process.

Technical details

A vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) exists in NVIDIA Triton Inference Server for Linux. The flaw allows a remote attacker to bypass security controls by utilizing an alternative communication path that does not properly enforce authentication. If successfully exploited, this could lead to unauthorized information disclosure, privilege escalation, and potentially remote code execution. The vulnerability affects versions up to and including 26.04. Mitigation or patching information was not explicitly detailed in the advisory, but users are generally advised to update to the latest supported version.

Affected products

  • NVIDIA Triton Inference Server <= 26.04

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record.

References

Related threats