Description
Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from a protection mechanism failure in Intel Data Center Attestation Primitives. An unprivileged, unauthenticated attacker can exploit the flaw with low complexity, potentially exposing sensitive data and compromising the integrity of the system. No user interaction is needed, and the attack may occur over the network with special internal knowledge, leading to downstream confidentiality impacts.

Affected Systems

Intel Data Center Attestation Primitives (Intel DCAP) is the affected product. Specific product versions are not enumerated in the available data, so all installations of Intel DCAP should be considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 8.9 indicates a high severity risk; however, the EPSS score of <1% suggests that the likelihood of exploitation remains low at present. The vulnerability is not listed in the CISA KEV catalog, but its high potential for integrity compromise warrants close attention. Attackers would likely leverage the network interface to reach DCAP, necessitating no user interaction and presenting a simple execution pathway for those with internal knowledge.

Generated by OpenCVE AI on August 12, 2026 at 21:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Intel DCAP update that addresses the protection mechanism failure.
  • If an update is not yet available, limit remote access to the DCAP service to trusted hosts only.
  • Monitor network traffic for attempts to exploit DCAP and investigate anomalous access patterns.

Generated by OpenCVE AI on August 12, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel dcap
Vendors & Products Intel
Intel dcap

Wed, 12 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Intel DCAP Protection Mechanism Failure Enabling Integrity Compromise

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Weaknesses CWE-693
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T15:49:57.747Z

Reserved: 2025-12-18T04:00:20.431Z

Link: CVE-2026-20702

cve-icon Vulnrichment

Updated: 2026-08-12T15:49:53.513Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:49.090

Modified: 2026-08-12T20:54:11.500

Link: CVE-2026-20702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:24:45Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure