
🚨 CVE-2026-24207 PoC for NVIDIA Triton Inference Server https://github.com/offseckit/CVE-2026-24207 CVE-2026-24207, a critical auth bypass affecting NVIDIA Triton Inference Server. The flaw impacts versions prior to r26.03 and may allow unauthenticated access to the model-management surface. Under certain conditions, researchers say it can be chained to pre-auth RCE as the Triton process user. Repo includes: • Detection script • Auth bypass demo • RCE-chain PoC • Suricata / IDS rules • Root-cause notes • Patch-diff docs Details: • Product: NVIDIA Triton Inference Server • CVE: CVE-2026-24207 • Severity: Critical • CVSS: 9.8 • CWE: CWE-288 • Fixed version: r26.03+ Admins should update Triton Server to r26.03 or later.
Post summary
The post announces a PoC for CVE‑2026‑24207 on NVIDIA Triton Inference Server, detailing an auth bypass and chained RCE, and advises updating to version r26.03+ as the recommended mitigation.







