boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-47606

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0074   53.0     —
AFFECTED
  Product                  Versions     Fixed
  Triton Inference Server  0.0-26.05 –  —
TIMELINE
  May 19  Reserved by nvidia
  Aug 18  Published (CNA: nvidia)
  Sep 2   RESCORED — CVE-2026-47606 (NVIDIA Triton Inference Server). CVSS 6.5 → 9.1 (NVD).
CWE-36 · CNA: nvidia · CVSS v3.1 · 3 references · NVD status: Analyzed

Description

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 19, 2026ReservedReserved by nvidia
August 18, 2026PublishedPublished (CNA: nvidia)
September 2, 2026RESCOREDRESCORED — CVE-2026-47606 (NVIDIA Triton Inference Server). CVSS 6.5 → 9.1 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
NVIDIATriton Inference Server—0.0-26.05—

Weaknesses

CWE-36

References (3)

Related

Authoritative record: CVE-2026-47606 at cve.org

Vendors: nvidia

Weaknesses: CWE-36

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-47606 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.