Description
Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a protection‑mechanism failure in Intel Extension for TensorFlow software before version 2.15.0.3 that allows a user application to gain higher privileges. An attacker can use the flaw to lift privileges within the system, potentially compromising the confidentiality and integrity of the affected system. The impact is listed as high for confidentiality, integrity, and availability, but the realistic consequence for the overall system is none, indicating that the flaw primarily affects the local user context.

Affected Systems

Intel Extension for TensorFlow software versions prior to 2.15.0.3 on any platform that uses the TensorFlow extension. The vulnerability applies to all installations that run the unpatched version within a user’s application space.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% reflects a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog, further lowering its exposure risk. The attack is local and requires a system‑software adversary to have privileged user access and a low‑complexity attack, combined with passive user interaction. If the conditions are met, an attacker can elevate privileges and gain unauthorized control over the system, but the overall risk remains moderate due to the low likelihood of exploitation.

Generated by OpenCVE AI on August 12, 2026 at 21:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Intel Extension for TensorFlow to version 2.15.0.3 or newer.
  • Restrict privileged user accounts from running untrusted applications that load the TensorFlow extension.
  • Apply principle of least privilege to all local user accounts and monitor for abnormal privilege elevation attempts.

Generated by OpenCVE AI on August 12, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel extension For Tensorflow Software
Vendors & Products Intel
Intel extension For Tensorflow Software

Wed, 12 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Protection Mechanism Failure Enabling Privilege Escalation in Intel Extension for TensorFlow

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Weaknesses CWE-693
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Intel Extension For Tensorflow Software
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T19:09:19.126Z

Reserved: 2025-12-19T04:00:14.877Z

Link: CVE-2026-20728

cve-icon Vulnrichment

Updated: 2026-08-12T19:03:14.142Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:50.250

Modified: 2026-08-12T20:54:11.500

Link: CVE-2026-20728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:23:30Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure