Arbitrary Code Execution Vulnerability in UEFI Firmware by Insyde Software
CVE-2026-6484

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-6484?

The UEFI firmware developed by Insyde Software is susceptible to a security vulnerability that allows for arbitrary code execution. This issue arises due to the absence of verified boot processes for certain firmware volumes (FVs). If exploited, this flaw may enable malicious actors to execute unauthorized code, potentially compromising the system's integrity and security.

Affected Version(s)

InsydeH2O x86 See in the Solution

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks to Nikolaj Schlej, independent firmware security researcher, for reporting the vulnerability and engaging in this coordinated disclosure.
.