Information Disclosure in UEFI Firmware of Intel Reference Platforms
CVE-2026-20712

4MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 August 2026

What is CVE-2026-20712?

An incomplete cleanup within the UEFI firmware on certain Intel reference platforms can lead to potential information disclosure. A system software adversary with elevated privileges can exploit this gap with relative ease, enabling unauthorized data exposure through local access. This vulnerability requires specific conditions to be met, allowing it to be carried out without special insider knowledge and without the need for user interaction. As a result, the confidentiality of the impacted system may be at risk, potentially leading to further security concerns.

Affected Version(s)

Intel(R) reference platforms See references

References

CVSS V4

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.