PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47487 NVIDIA CVE debrief

The CVE-2026-47487 vulnerability affects NVIDIA Triton Inference Server for Linux, allowing users to read, write, or modify files outside the model repository by manipulating the model name in the Triton MLflow plugin. This could lead to denial of service and information disclosure. Organizations should review and apply patches from NVIDIA and restrict access to the model repository. Evidence is limited, and further verification is needed to fully understand the vulnerability's impact.

Vendor
NVIDIA
Product
Triton Inference Server
CVSS
MEDIUM 4.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-04
Original CVE updated
2026-08-06
Advisory published
2026-08-04
Advisory updated
2026-08-06

Who should care

Organizations using NVIDIA Triton Inference Server for Linux should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and applying patches from NVIDIA, restricting access to the model repository, and monitoring for suspicious activity. Security teams should prioritize patching this vulnerability to prevent potential denial of service and information disclosure. IT teams should verify that the Triton MLflow plugin is properly configured and secured. Operators should be cautious when using the Triton Inference Server and report any suspicious activity to the security team. Vulnerability management teams should ensure that all affected systems are patched or mitigated. Platform administrators should review the system configuration and ensure that it is secure. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Asset inventory teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Source tracking teams should verify the source of the vulnerability and ensure that all affected systems are patched or mitigated. Rollback and change window teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating control teams should review compensating controls for exposed systems while remediation is scheduled and verified. Exposure review teams should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Monitoring teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Asset inventory teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Source tracking teams should verify the source of the vulnerability and ensure that all affected systems are patched or mitigated. Rollback and change window teams should plan vendor-supported updates or mitigations through normal change

Technical summary

The vulnerability in NVIDIA Triton Inference Server for Linux allows a user to cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. This could lead to denial of service and information disclosure. The vulnerability is caused by improper input validation in the Triton MLflow plugin, which allows an attacker to manipulate the model name and access files outside the model repository.

Defensive priority

Organizations using NVIDIA Triton Inference Server for Linux should prioritize patching this vulnerability to prevent potential denial of service and information disclosure.

Recommended defensive actions

  • Review and apply patches from NVIDIA for CVE-2026-47487
  • Restrict access to the model repository and monitor for suspicious activity
  • Verify that the Triton MLflow plugin is properly configured and secured
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE description indicates that NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. Evidence is limited, and further verification is needed to fully understand the vulnerability's impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T18:16:50.490Z and has not been modified since then.