CVE-2026-24207
NVIDIA Triton Inference Server has a critical authentication bypass that allows unauthenticated users to access privileged functions. The flaw could enable attackers to run code, modify data, or disrupt service. It is rated CVSS 9.8.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
NVIDIA Triton Inference Server on Linux systems (all versions).
Real-world impact
An attacker could execute arbitrary code, gain elevated privileges, tamper with data, or cause denial of service on the affected server.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network with no authentication, provides full compromise of confidentiality, integrity, and availability, and requires no special privileges or user interaction.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 20, 2026 · May 20, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- nvd.nist.gov/vuln/detail/CVE-2026-24207third party advisoryus government resource
- nvidia.custhelp.com/app/answers/detail/a_id/582…vendor advisory
- cve.org/CVERecordthird party advisory