
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47630 is an absolute path traversal vulnerability in NVIDIA Triton Inference Server for Linux that could allow an attacker to traverse outside restricted directories, potentially leading to code execution. It affects Triton Inference Server version 0.0-26.05 on Linux platforms. The vulnerability was published on August 18, 2026, as part of NVIDIA Security Bulletin 5865. It carries a CVSS v3.1 base score of 5.5 (Medium), assigned by NVIDIA Corporation (NVIDIA Advisory, NVD).
The vulnerability is classified as CWE-36 (Absolute Path Traversal), meaning the software does not properly restrict user-supplied path inputs to a designated directory, allowing an attacker to specify absolute paths that resolve to arbitrary locations on the filesystem. Exploitation requires local access with low privileges and no user interaction, suggesting the attack vector involves a locally authenticated user or process supplying a crafted path to the Triton Inference Server. A successful exploit could lead to code execution, though the specific vulnerable component or API endpoint within Triton has not been publicly detailed beyond the NVIDIA security bulletin (NVIDIA Advisory, NVD).
Successful exploitation of this vulnerability primarily impacts confidentiality, with a high confidentiality impact rating and no direct integrity or availability impact per the CVSS scoring. An attacker with local low-privilege access could read arbitrary files outside the intended directory scope of the Triton Inference Server, potentially exposing sensitive model data, configuration files, or system credentials. In a worst-case scenario, the path traversal could be chained to achieve code execution, which could further compromise the host system or AI/ML inference infrastructure (NVD, NVIDIA Advisory).
As of the disclosure date (August 18, 2026), there is no evidence of active in-the-wild exploitation, no public proof-of-concept code, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. CISA's SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable with only partial technical impact. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term (NVD).
NVIDIA has published Security Bulletin 5865 addressing this vulnerability in Triton Inference Server. Users should consult the official NVIDIA security bulletin for patched version information and apply the recommended update. As a general workaround, restrict local access to Triton Inference Server instances to trusted users only, and enforce least-privilege principles for any accounts or processes interacting with the server (NVIDIA Advisory).
The vulnerability received routine coverage from automated vulnerability tracking services such as VulDB and CVEFeed shortly after publication, and was noted on social platforms including Mastodon (infosec.exchange) and Bluesky. No significant researcher commentary or vendor statements beyond the official NVIDIA bulletin have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."