What is CVE-2026-47487?
CVE-2026-47487 is a path traversal vulnerability in NVIDIA Triton Inference Server on Linux, exploitable via the MLflow plugin by injecting paths into model names. This allows unauthorized file read, write, or modification outside the model repository, potentially leading to denial of service.
Azərbaycanca: CVE-2026-47487 NVIDIA Triton Inference Server üçün Linux mühitində path traversal zəifliyidir. MLflow plugin-i vasitəsilə model adında xüsusi fayl yolu təqdim etməklə, istifadəçi model anbarından kənar faylları oxuya, yaza və ya dəyişə bilər ki, bu da xidmət dayanmasına səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: NVIDIA
FAQ2
In which environment can CVE-2026-47487 be exploited?
CVE-2026-47487 is exploitable in NVIDIA Triton Inference Server on Linux.
What can CVE-2026-47487 lead to?
Exploiting this vulnerability can allow unauthorized read, write, or modification of files outside the model repository, potentially leading to denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.