External risk intelligence

NVIDIA Triton Inference Server Path Traversal Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-47606

NVIDIA Triton Inference Server is a model-serving solution commonly deployed as a network-accessible API or edge service to process requests. Because it is designed to handle inference requests in production environments, it is frequently exposed as a reachable web or API endpoint.

Path Traversal

Nvidia Triton Inference Server

26.05 and earlier

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in NVIDIA's Triton Inference Server for Linux, which could allow an unauthenticated attacker to execute code or disclose information through an absolute path traversal. The main concern is confirming relevance and exposure.

  • Path traversal flaw in NVIDIA Triton Server.
  • Critical flaw could lead to code execution.
  • Confirm relevance and exposure of affected systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted requests to the NVIDIA Triton Inference Server. This could allow them to traverse directories on the server's file system, potentially leading to code execution or the disclosure of sensitive information.

  • No authentication required for access.
  • Path traversal in server requests.
  • Code execution and data exposure possible.

Live Threat

Current exploitation, exposure, and threat context

An attacker could exploit a vulnerability in NVIDIA Triton Inference Server to cause an absolute path traversal. When supported by the advisory, this could lead to code execution and disclosure of system information.

  • System files could be accessed.
  • Absolute path traversal may occur.
  • Code execution and data disclosure.

Operational Fix

Recommended remediation, mitigation, and detection steps

Ownership for this vulnerability likely falls to the platform or infrastructure teams managing the NVIDIA Triton Inference Server deployments, in coordination with the application owners who utilize the inference capabilities. The initial practical step is to identify all Triton instances, determine their network reachability and business criticality, and then engage the accountable owner to plan a risk-based remediation strategy.

  • Platform and application owners should drive remediation.
  • Verify Triton instances and their exposure.
  • Plan and coordinate vendor-assisted updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is NVIDIA Triton Inference Server?

It is a specialized software tool used to deploy and scale artificial intelligence models. Organizations use it to serve deep learning models in production, allowing applications to send data to the server and receive model predictions back. It is designed to handle high-performance inference workloads across different model frameworks.

What does absolute path traversal mean for CVE-2026-47606?

This vulnerability, classified as CWE-36 (Absolute Path Traversal), allows an attacker to bypass intended file system restrictions. Instead of being limited to specific folders, a user can provide a full file path to access or manipulate restricted files on the host system. This weakness can potentially result in the server executing malicious code or revealing sensitive data that should be private.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending specially crafted requests directly to the Triton Inference Server. The flaw does not require the attacker to have an existing user account or special permissions to interact with the system. Simply making an unauthorized request containing a malicious path is enough to potentially bypass security controls; the vulnerability is not triggered by standard, legitimate model inference traffic.

Is my server at risk according to Halo Surface Signal?

NVIDIA Triton Inference Server is often deployed as a network-accessible API or edge service to process production requests, which increases the likelihood of reachability. If your instance is configured as a web or API endpoint exposed to the network, Halo Surface Signal suggests it is a priority for review because it is designed to be accessible for incoming model requests.

When should I take action for this vulnerability?

You should begin by identifying every Triton Inference Server instance running in your environment. Once mapped, coordinate with your infrastructure or platform teams to verify the network exposure of each system and assess its business criticality. After confirming which instances are active, prepare to coordinate with your vendor to apply the necessary security updates.

References