Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-47625
Triton Inference Server vulnerability analysis and mitigation

Overview

CVE-2026-47625 is a missing authorization vulnerability in NVIDIA Triton Inference Server for Linux that allows network-accessible attackers to exploit the server without authentication. The vulnerability affects Triton Inference Server version 0.0-26.03 and was published on September 8, 2026, as part of NVIDIA Security Bulletin 5875. Successful exploitation may lead to information disclosure, data tampering, and denial of service. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, NVIDIA Product Security).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the server fails to enforce proper access controls on one or more of its endpoints or operations. Because no authentication or authorization check is required, a remote attacker can send crafted network requests to trigger unintended server behavior. The vulnerability is automatable and requires no user interaction or special privileges, making it straightforward to exploit at scale (Feedly, NVIDIA Product Security). No public proof-of-concept code has been identified at this time.

Impact

Exploitation of this vulnerability can result in information disclosure, data tampering, and denial of service against affected Triton Inference Server deployments. The availability impact is rated High, meaning an attacker could disrupt inference services, potentially affecting AI/ML workloads and downstream applications that depend on the server. Data tampering could allow an attacker to manipulate model inputs or outputs, undermining the integrity of inference results (Feedly).

Exploitability

No in-the-wild exploitation has been reported, and no proof-of-concept exploit code is publicly available as of the time of this report (Feedly). The vulnerability is classified as automatable by NVD SSVC, indicating it can be exploited at scale without manual interaction. The EPSS score is approximately 0.399%, reflecting a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Mitigation and workarounds

NVIDIA has addressed this vulnerability in Security Bulletin 5875, which covers Triton Inference Server. Users should consult the official NVIDIA bulletin for the specific patched version and apply the recommended update as soon as possible. As a general workaround, restrict network access to Triton Inference Server endpoints using firewalls or network segmentation to limit exposure to trusted clients only. Enabling authentication and authorization mechanisms available in Triton (such as those provided via NVIDIA Triton's security configuration options) is also strongly recommended (NVIDIA Product Security).

Community reactions

Security aggregators including SecurityOnline.info and VulDB have indexed this vulnerability shortly after disclosure, indicating moderate community awareness (Feedly). No notable researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related Triton Inference Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47625HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoSep 08, 2026
CVE-2026-16497HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoSep 08, 2026
CVE-2026-47629HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoAug 18, 2026
CVE-2026-47628HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoAug 18, 2026
CVE-2026-47630MEDIUM5.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management