Impact
NVIDIA Triton Inference Server enables an attacker to bypass authentication by using an alternative path or channel, which could allow the attacker to execute arbitrary code, elevate privileges, disclose information, and tamper with data. The weakness is classified as CWE‑288, indicating an authentication bypass flaw that undermines the entire security model of the service.
Affected Systems
The vulnerability affects NVIDIA Triton Inference Server running on Linux. No specific version information is listed, so all current releases may be susceptible until an update is released.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score is below 1%, so the likelihood of exploitation is presently low, and the vulnerability is not listed in CISA’s KEV catalog. The attack likely originates from a network‑connected client interacting with the inference server’s API, using an undocumented or insecure channel to trigger the authentication bypass. An attacker who can reach the server can take advantage of the flaw to gain unauthorized code execution beyond normal privileges.
OpenCVE Enrichment