PatchSiren cyber security CVE debrief
CVE-2026-24208 NVIDIA CVE debrief
CVE-2026-24208 is a medium-severity path traversal vulnerability in NVIDIA Triton Inference Server. According to official records, a successful network-based attack with no privileges and no user interaction could result in denial of service. The NVD record maps the issue to CWE-22 and lists affected Triton Inference Server versions before 26.03.
- Vendor
- NVIDIA
- Product
- Triton Inference Server
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-24
Who should care
Security teams and operators running NVIDIA Triton Inference Server, especially if the service is reachable over the network or exposed in production ML inference environments.
Technical summary
Official NVD data describes the flaw as a path traversal issue in NVIDIA Triton Inference Server. The published CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L (5.3, Medium), indicating a remotely reachable issue with low attack complexity and an availability impact. NVD CPE criteria mark nvidia:triton_inference_server versions with endExcluding 26.03 as vulnerable; the Linux kernel CPE entry in the same record is marked not vulnerable.
Defensive priority
Medium priority. Treat as higher urgency if Triton Inference Server is internet-facing, multi-tenant, or business-critical.
Recommended defensive actions
- Confirm whether any environment runs NVIDIA Triton Inference Server.
- Check deployed Triton versions and compare them with the NVD affected range (versions before 26.03).
- Apply the vendor fix or upgrade to a non-vulnerable release per NVIDIA guidance.
- Use the NVIDIA advisory and CVE/NVD records as the authoritative reference for remediation timing and scope.
- After remediation, verify service availability and review logs for unexpected path-related request failures or instability.
Evidence notes
This debrief is based only on official sources in the supplied corpus: NVD, CVE.org, and the NVIDIA PSIRT advisory referenced by NVD. The NVD record is marked VulnStatus: Analyzed, published 2026-05-20T04:16:46.177Z and modified 2026-05-20T17:29:44.640Z. NVD lists the weakness as CWE-22 and the CVSS vector as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L. The affected CPE criteria identify NVIDIA Triton Inference Server as vulnerable before 26.03.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-24208 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-24208
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-24208 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24208
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://nvidia.custhelp.com/app/answers/detail/a_id/5828
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.