Critical Authentication Bypass Vulnerability in NVIDIA Triton Inference Server

Critical Authentication Bypass Vulnerability in NVIDIA Triton Inference Server

First seen 20 May 2026, 19:05 UTC GbhackersLetsdatascience 80% similarity 72.8

Article Content

Browse articles
ThreatCluster

NVIDIA disclosed a critical authentication-bypass vulnerability in its Triton Inference Server, tracked as CVE-2026-24207, with a CVSS v3.1 score of 9.8. This flaw allows remote exploitation without credentials, potentially leading to unauthorized code execution, privilege escalation, data tampering, and denial-of-service. Organizations using Triton for AI inference workloads are at significant risk. Reporting on patch availability is inconsistent; some sources indicate a patch exists for versions before r26.03, while others have not confirmed any patch. The vulnerability arises from improper authentication controls and is accessible via network attack vectors. Security experts recommend immediate action for affected organizations to mitigate risks. The NVD entry for this CVE is currently undergoing enrichment.

Key Points: • CVE-2026-24207 has a CVSS score of 9.8, indicating critical severity. • The vulnerability allows remote exploitation without prior authentication. • Patching status is inconsistent; some sources confirm a patch while others do not.

ThreatCluster AI

Timeline

2026-05-20
CVE-2026-24207 published
NVIDIA disclosed a critical authentication-bypass vulnerability in Triton Inference Server, allowing remote exploitation.
Letsdatascience
2026-05-20
Vulnerability reported by multiple outlets
Security outlets reported the flaw, highlighting its potential for unauthorized access and severe impact on AI workloads.
Gbhackers

Community

Browse all →