id: CVE-2026-24207 info: name: NVIDIA Triton Inference Server <= 26.02 - Authentication Bypass author: VixianSchool severity: critical description: | NVIDIA Triton Inference Server contains an authentication bypass vulnerability, letting attackers bypass authentication and potentially execute code, escalate privileges, tamper data, cause denial of service, or disclose information, exploit requires no special conditions. impact: | Attackers can bypass authentication to execute code, escalate privileges, tamper data, cause denial of service, or disclose sensitive information. remediation: | Update to the latest version of NVIDIA Triton Inference Server. reference: - https://github.com/offseckit/CVE-2026-24207 - https://offseckit.com/blog/cve-2026-24207 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2026-24207 epss-score: 0.02552 epss-percentile: 0.83385 cwe-id: CWE-288 metadata: verified: true max-request: 2 vendor: nvidia product: triton-inference-server shodan-query: 'http.title:"Triton" port:8080' tags: cve,cve2026,nvidia,triton,auth-bypass,rce,ml,ai http: - method: GET path: - "{{BaseURL}}/models" matchers: - type: dsl dsl: - "status_code == 200" - "contains(body, '\"models\":[')" - "!contains(body, 'This API is restricted')" - "!contains(body, 'restricted')" condition: and # digest: 4a0a00473045022100bcba612b6d2b209c2aba6b2abbe8a3d2ecb1b732c64f21e20e85c4805101541c022004272a6061a3d3eab10d0f62028c3d2450bd170a77624f347653c330b7c3516c:922c64590222798bb761d5b6d8e72950