Description
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA Triton Inference Server enables an attacker to bypass authentication by using an alternative path or channel, which could allow the attacker to execute arbitrary code, elevate privileges, disclose information, and tamper with data. The weakness is classified as CWE‑288, indicating an authentication bypass flaw that undermines the entire security model of the service.

Affected Systems

The vulnerability affects NVIDIA Triton Inference Server running on Linux. No specific version information is listed, so all current releases may be susceptible until an update is released.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score is below 1%, so the likelihood of exploitation is presently low, and the vulnerability is not listed in CISA’s KEV catalog. The attack likely originates from a network‑connected client interacting with the inference server’s API, using an undocumented or insecure channel to trigger the authentication bypass. An attacker who can reach the server can take advantage of the flaw to gain unauthorized code execution beyond normal privileges.

Generated by OpenCVE AI on July 31, 2026 at 05:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Triton or any vendor security update as soon as it becomes available.
  • Limit exposure by restricting inbound traffic to the inference server to trusted hosts or networks.
  • Enforce strict authentication on all API endpoints, ensuring no alternate or insecure paths are available; consider disabling or protecting the vulnerable channel.

Generated by OpenCVE AI on July 31, 2026 at 05:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Alternative Path in NVIDIA Triton Inference Server

Wed, 29 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA Triton Inference Server Leading to Code Execution

Sat, 25 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in NVIDIA Triton Inference Server Leading to Code Execution

Wed, 22 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Allowing Code Execution in NVIDIA Triton Inference Server

Fri, 17 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Allowing Code Execution in NVIDIA Triton Inference Server

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia triton Inference Server
Vendors & Products Nvidia
Nvidia triton Inference Server

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Nvidia Triton Inference Server
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-15T14:13:24.115Z

Reserved: 2026-05-19T19:55:39.687Z

Link: CVE-2026-47481

cve-icon Vulnrichment

Updated: 2026-07-15T14:13:20.329Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel