Improper Access Control in Intel(R) Xeon(R) Processor Firmware
CVE-2026-20898
Key Information:
- Vendor
Intel
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-20898?
A security flaw in the firmware for certain Intel Xeon processors allows for improper access control, which may enable an escalation of privilege. Exploiting this vulnerability requires a high complexity attack, with adversaries gaining potential access under specific conditions, typically through local means. The vulnerability does not necessitate user interaction, heightening its risk profile. The implications can compromise system confidentiality and integrity, presenting significant security concerns for affected systems.
Affected Version(s)
in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts. See references