Executive brief
NVIDIA Triton Inference Server is a software platform used to deploy and run machine learning models for inference workloads. Missing authorization controls in the Linux version allow unauthenticated attackers to access the service, potentially exposing sensitive model data, modifying inference results, or causing service unavailability.
Technical details
The vulnerability involves missing authorization checks in NVIDIA Triton Inference Server for Linux, allowing attackers to bypass access controls. An attacker with network access to the service can exploit this to perform unauthorized actions without proper authentication. The vulnerability enables information disclosure (reading model data and inference outputs), data tampering (modifying model behavior or results), and denial of service. The attack vector is network-based and requires no authentication or user interaction. Patches are expected from NVIDIA; consult their security bulletin for affected versions and remediation guidance.
Affected products
- NVIDIA Triton Inference Server <UNKNOWN>
Timeline
- 2026-09-08: disclosed