Description
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
Published: 2026-09-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access Leading to Data Disclosure, Tampering, and Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing authorization control (CWE-862) in NVIDIA Triton Inference Server for Linux. An attacker could take advantage of the lack of authentication and send privileged commands to the server’s API endpoints without credentials. This could result in sensitive information being exposed, manipulation of inference model parameters or outputs, and disruption of service operations, as noted in the official description of possible information disclosure, data tampering, and denial of service. The impact is therefore primarily data confidentiality, integrity, and availability for any systems relying on the inference service.

Affected Systems

Vendor NVIDIA; product Triton Inference Server; platform Linux. Specific affected versions were not disclosed in the advisory; any unpatched instance is assumed vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can exploit the server remotely by interacting with exposed API endpoints without authentication. The absence of an authorization control makes such exploitation straightforward for any adversary with network reach to the server, raising the risk to environments where the inference service is exposed to untrusted networks.

Generated by OpenCVE AI on September 8, 2026 at 19:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Triton Inference Server release that includes the authorization fix
  • Configure the server to require authentication for all API endpoints and restrict network access to trusted hosts
  • Monitor incoming requests for anomalous activity and audit logs for unauthorized access attempts

Generated by OpenCVE AI on September 8, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Missing Authorization in NVIDIA Triton Inference Server Leading to Data Disclosure and Denial of Service Unauthorized Access in NVIDIA Triton Inference Server Allows Data Disclosure and Service Disruption

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Missing Authorization in NVIDIA Triton Inference Server Leading to Data Disclosure and Denial of Service
First Time appeared Nvidia
Nvidia triton Inference Server
Vendors & Products Nvidia
Nvidia triton Inference Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Nvidia Triton Inference Server
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-08T18:01:46.533Z

Reserved: 2026-05-19T19:55:52.529Z

Link: CVE-2026-47625

cve-icon Vulnrichment

Updated: 2026-09-08T18:01:43.276Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T17:17:37.683

Modified: 2026-09-08T19:17:58.267

Link: CVE-2026-47625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:15:16Z

Weaknesses