CVE-2026-24207Disclosure(linux / linux_kernel)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel
  • triton_inference_server

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 3 mentions (2026-05-20); latest day: 2
  • 9 total mentions across 6 days

Affected systems

Products
linux_kerneltriton_inference_server

1 version affected across 2 products

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-05-20: 3Mentions · 2026-05-22: 1Mentions · 2026-06-06: 1Mentions · 2026-06-27: 1Mentions · 2026-07-13: 1Mentions · 2026-07-17: 2PoC Mentioned / Linked · 2026-06-27: 1PoC Mentioned / Linked · 2026-07-13: 1PoC Mentioned / Linked · 2026-07-17: 2Exploit Tool / Code · 2026-06-27: 1Patch / Workaround · 2026-05-20: 2Patch / Workaround · 2026-06-27: 1Technical Details · 2026-05-20: 3Technical Details · 2026-05-22: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-13: 105-2005-2206-0606-2707-1307-17
Signal classification4 categories
Disclosure
333.3%
PoC
333.3%
Patch
222.2%
General
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-203
Disclosure1Patch2
2026-05-221
Disclosure1
2026-06-061
General1
2026-06-271
PoC1
2026-07-131
Disclosure1
2026-07-172
PoC2
Full discourse9 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    🚨 CVE-2026-24207 PoC for NVIDIA Triton Inference Server https://github.com/offseckit/CVE-2026-24207 CVE-2026-24207, a critical auth bypass affecting NVIDIA Triton Inference Server. The flaw impacts versions prior to r26.03 and may allow unauthenticated access to the model-management surface. Under certain conditions, researchers say it can be chained to pre-auth RCE as the Triton process user. Repo includes: • Detection script • Auth bypass demo • RCE-chain PoC • Suricata / IDS rules • Root-cause notes • Patch-diff docs Details: • Product: NVIDIA Triton Inference Server • CVE: CVE-2026-24207 • Severity: Critical • CVSS: 9.8 • CWE: CWE-288 • Fixed version: r26.03+ Admins should update Triton Server to r26.03 or later.

    Post summary

    The post announces a PoC for CVE‑2026‑24207 on NVIDIA Triton Inference Server, detailing an auth bypass and chained RCE, and advises updating to version r26.03+ as the recommended mitigation.

    1170932714.1K
    226.8K followersView on X
  • yousukezan@yousukezan
    Patch

    NVIDIAがAI推論基盤「Triton Inference Server」の重大脆弱性群を修正した。認証回避を引き起こすCVSS 9.8のCVE-2026-24207を含み、コード実行や権限昇格、情報漏えいへつながる恐れがあった。 最も深刻なCVE-2026-24207はTriton Inference Server本体に存在し、攻撃者が認証を回避できる。悪用されると任意コード実行、権限昇格、データ改ざん、DoS、情報漏えいが発生する可能性がある。 加えてDALIバックエンドでも複数欠陥が修正された。CVE-2026-24213は境界外読み取り、CVE-2026-24214は整数オーバーフロー、CVE-2026-24215はリソース消費制御不備に関する問題で、コード実行やDoSにつながる危険がある。 さらにCVE-2026-24209とCVE-2026-24208ではパストラバーサル、CVE-2026-24210では整数オーバーフロー、CVE-2026-24206では追加の認証回避問題も確認された。これらは主にLinux環境のTriton ServerおよびDALI Backendへ影響する。 https://securityonline.info/nvidia-triton-inference-server-vulnerability-cve-2026-24207-authentication-bypass/

    Post summary

    NVIDIA has released a patch for multiple critical CVEs in Triton Inference Server, detailing authentication bypass, code execution, and other vulnerabilities, but no PoC or evidence of active exploitation is presented.

    030822.2K
    14.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-24207 - critical 🚨 NVIDIA Triton Inference Server <= 26.02 - Authentication Bypass > NVIDIA Triton Inference Server contains an authentication bypass vulnerability, letti... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-24207 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces a critical authentication bypass vulnerability in NVIDIA Triton Inference Server (≤ 26.02) and links to a Project Discovery library entry, but does not provide exploit code or evidence of active exploitation.

    02052520
    1.3K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    NVIDIA patches a critical 9.8 CVSS authentication bypass (CVE-2026-24207) in Triton Inference Server. Update to r26.03 to secure AI workloads! #NVIDIA #TritonServer #CyberSecurity #InfoSec #VulnerabilityAlert #CVE #AISecurity #MachineLearning #PatchNow https://securityonline.info/nvidia-triton-inference-server-vulnerability-cve-2026-24207-authentication-bypass/

    Post summary

    NVIDIA released patch r26.03 to address a critical authentication bypass (CVE‑2026‑24207) in Triton Inference Server, noting the CVSS score of 9.8.

    01030400
    12.5K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Vendor. 0day Intel: 🚨 CVE-2026-24207 PoC for NVIDIA Triton Inference Server

    Post summary

    A PoC has been announced for CVE-2026-24207 targeting NVIDIA Triton Inference Server, with no additional exploit details or patch information disclosed.

    1000043
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-24207. 0day Intel: 🚨 CVE-2026-24207 PoC for NVIDIA Triton Inference Server

    Post summary

    The tweet announces a proof‑of‑concept for CVE‑2026‑24207 on NVIDIA Triton Inference Server, without providing exploit details, patch information, or evidence of active exploitation.

    1000046
    326 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-24207: NVIDIA Triton Inference Server Authentication Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04kpl4Q0

    Post summary

    The snippet appears to reference a general informational article on CVE‑2026‑24207 but does not supply PoC details, exploitation evidence, patch info, or technical specifics.

    0000029
    32 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    NVIDIA Triton Inference ServerにCVSS 9.8の認証回避 脆弱性(CVE-2026-24207) https://rocket-boys.co.jp/security-measures-lab/nvidia-triton-auth-bypass-cve-2026-24207/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post announces a new authentication‑bypass vulnerability in NVIDIA Triton Inference Server (CVE‑2026‑24207) with a CVSS score of 9.8 and directs readers to a security‑lab article for details.

    00000149
    407 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24207 NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead … https://www.cve.org/CVERecord?id=CVE-2026-24207

    Post summary

    The post announces CVE‑2026‑24207, an authentication bypass flaw in NVIDIA Triton Inference Server, without offering PoC, exploit details, or patch information.

    00000161
    57.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
Appnvidiatriton_inference_server---

Explore more