Description
Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Incomplete cleanup in certain UEFI firmware on Intel reference platforms allows system software adversaries with privileged user accounts to read residual data stored temporarily during firmware operations. This information disclosure can be achieved with low complexity local attacks that do not require user interaction, provided the attacker meets the access prerequisites. Although the CVSS analysis indicates no direct impact on confidentiality, integrity, or availability, the resulting system confidentiality impact is high, exposing potentially sensitive information.

Affected Systems

This vulnerability affects UEFI firmware on Intel reference platforms. Specific firmware versions are not disclosed in the advisory, so all UEFI builds shipped with these reference platforms should be considered potentially vulnerable until a patch is released.

Risk and Exploitability

With a CVSS base score of 4 and an EPSS below 1%, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring privileged access and no special knowledge; therefore organizations with privileged users on these platforms should remain vigilant. Even though the probability is low, the severity of a potential data leakage warrants monitoring of firmware updates and access controls.

Generated by OpenCVE AI on August 12, 2026 at 20:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest UEFI firmware updates for Intel reference platforms that address the cleanup issue.
  • Restrict privileged local access to only those users who require it, and enforce least‑privilege policies.
  • Perform an audit of temporary storage usage in the firmware and document any residual sensitive data that may be left behind.
  • Monitor for any anomalies or evidence of data leakage following firmware deployment and consider forensic review if exposure is suspected.

Generated by OpenCVE AI on August 12, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel intel Reference Platforms
Vendors & Products Intel
Intel intel Reference Platforms

Wed, 12 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title UEFI Firmware Temporary Storage Disclosure on Intel Reference Platforms

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Weaknesses CWE-459
References
Metrics cvssV4_0

{'score': 4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Intel Intel Reference Platforms
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T13:36:09.278Z

Reserved: 2025-12-03T17:58:55.176Z

Link: CVE-2026-20712

cve-icon Vulnrichment

Updated: 2026-08-12T13:36:03.208Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T18:17:24.460

Modified: 2026-08-12T20:54:11.500

Link: CVE-2026-20712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:52Z

Weaknesses