Escalation of Privilege in Intel Xeon Processor Firmware
CVE-2026-20901

4MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 August 2026

What is CVE-2026-20901?

A vulnerability in Intel Xeon processor firmware may allow unauthorized users to escalate privileges due to improper input validation. Attackers with local access can exploit this flaw, necessitating a combination of advancements and user privilege. This exploit has implications for data integrity, potentially allowing modifications without necessary internal knowledge. Mitigation measures are recommended to safeguard systems against possible exploitation.

Affected Version(s)

Intel(R) Xeon(R) processors See references

References

CVSS V4

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.