Information Disclosure in Intel Management Technology
CVE-2026-20708

5.9MEDIUM

What is CVE-2026-20708?

A vulnerability within Intel's management subsystem can lead to the insertion of sensitive information into log files, potentially allowing unauthorized data exposure. Attackers, leveraging a network access vector and who possess certain privileges, might exploit this weakness to uncover sensitive data without requiring direct user interaction. This issue underscores the importance of maintaining rigorous security practices and monitoring network accesses to safeguard sensitive information.

Affected Version(s)

Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. See references

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.