Path Traversal Vulnerability in NVIDIA Triton Inference Server for Linux
CVE-2026-47487

4.4MEDIUM

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
4 August 2026

What is CVE-2026-47487?

The NVIDIA Triton Inference Server for Linux is susceptible to a path traversal vulnerability that can be exploited through the Triton MLflow plugin. By manipulating the model name to include a path, an attacker may gain unauthorized access to files outside of the designated model repository. This could allow them to read, write, or modify files, potentially leading to significant disruptions, including denial of service and information disclosure.

Affected Version(s)

Triton Inference Server Linux 0.0 - 26.02

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.