
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47606 is an absolute path traversal vulnerability in NVIDIA Triton Inference Server for Linux that could allow an unauthenticated remote attacker to traverse outside restricted directories. A successful exploit may lead to code execution and information disclosure. The affected version is listed as 0.0-26.05 (versions up through the May 2026 release), with all other versions marked as unaffected by default. It was published on August 18, 2026, as part of NVIDIA Security Bulletin 5865, and carries a CVSS v3.1 base score of 6.5 (Medium) assigned by NVIDIA Corporation (NVIDIA Advisory).
The vulnerability is classified as CWE-36 (Absolute Path Traversal), meaning the application fails to properly restrict file path inputs to a designated directory, allowing an attacker to supply absolute paths that reference arbitrary locations on the filesystem (NVIDIA Advisory). The attack vector is network-based, requires no authentication (no privileges required) and no user interaction, making it automatable according to CISA's SSVC assessment. The specific component within Triton Inference Server where the traversal occurs has not been publicly detailed beyond the CVE record at this time.
Successful exploitation could result in unauthorized read access to sensitive files on the host system (confidentiality impact: low) and the ability to write or manipulate files outside the intended directory scope (integrity impact: low), with no direct availability impact. In AI/ML inference server environments, exposed files could include model weights, configuration files, API keys, or other sensitive operational data. The potential for code execution noted in the advisory suggests that in certain configurations, an attacker may be able to escalate from file access to arbitrary command execution on the server (NVIDIA Advisory).
As of the publication date (August 18, 2026), there is no evidence of active in-the-wild exploitation, and no public proof-of-concept exploit code has been identified. CISA's SSVC assessment classifies the vulnerability with exploitation status of "none" but notes it is "automatable," indicating it can be exploited without manual interaction at scale. The EPSS score is reported at 0.0, reflecting low current probability of exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (NVIDIA Advisory).
NVIDIA has published Security Bulletin 5865 addressing this vulnerability; users should consult the bulletin for patched version details and apply the recommended update. The affected version range is listed as 0.0-26.05, so upgrading to a version released after May 2026 (as specified in the bulletin) is the primary remediation. As a network-accessible service, organizations should also consider restricting network access to Triton Inference Server endpoints to trusted clients only, and auditing file system permissions to limit the impact of any path traversal attempt (NVIDIA Advisory).
The vulnerability received routine coverage from vulnerability tracking platforms such as VulDB and CVEFeed shortly after publication, and was noted on social media platforms including Mastodon and Bluesky by automated CVE tracking accounts. No notable independent researcher commentary or significant media coverage has been identified beyond standard aggregator postings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."