
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24147 is a path traversal vulnerability (CWE-22) in NVIDIA Triton Inference Server that allows an unauthenticated remote attacker to cause information disclosure by uploading a malicious model configuration. All versions of Triton Inference Server prior to r26.02 are affected. The vulnerability was published on April 7, 2026, with an initial analysis by NIST completed on April 16, 2026. It carries a CVSS v3.1 base score of 4.8 (Medium), assigned by NVIDIA Corporation (Github Advisory, NVIDIA Advisory).
The vulnerability is rooted in improper limitation of a pathname to a restricted directory (CWE-22), where the Triton Inference Server fails to properly neutralize special path elements (e.g., ../ sequences) within model configuration uploads. An attacker can craft a malicious model configuration file containing path traversal sequences and upload it to the server, causing the server to access files outside the intended directory boundary. Exploitation requires network access but no authentication, no user interaction, and no special privileges, though attack complexity is rated High, suggesting some non-trivial precondition or race condition must be met (Github Advisory, NVIDIA Advisory).
Successful exploitation may lead to information disclosure — allowing an attacker to read sensitive files accessible to the Triton server process — or denial of service, potentially disrupting AI inference workloads. The scope is limited to the affected Triton Inference Server instance (unchanged scope), with low confidentiality impact and low availability impact, and no integrity impact. In environments where Triton has broad file system access or is co-located with sensitive data, the information disclosure risk could be more significant (Github Advisory, NVIDIA Advisory).
config.pbtxt) that includes path traversal sequences such as ../../ in fields that reference file paths, targeting sensitive files on the server's file system.../, %2e%2e%2f, ..%2f) in model configuration payloads./etc/passwd, configuration files) that the Triton process should not normally read.strace, auditd logs).NVIDIA has released a patch in Triton Inference Server version r26.02; all users should upgrade to this version or later (NVIDIA Advisory). As interim mitigations, restrict network access to the Triton server's model management API to trusted sources only using firewall rules or network segmentation. Run the Triton Inference Server with a least-privilege service account that has minimal file system access permissions. Monitor server logs for path traversal patterns in model configuration upload requests.
Security news outlet SecurityOnline.info covered the vulnerability as part of a broader NVIDIA DALI and Triton security update report. German technology publication Heise.de also reported on NVIDIA's security hardening of DALI and Triton Inference Server tools. No significant researcher commentary or social media discussion beyond standard vulnerability tracking has been observed for this specific CVE (SecurityOnline, Heise.de).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."