Description
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.
Published: 2026-08-11
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in firmware of certain Intel Xeon processors may allow an attacker with privileged local access to modify system data. The flaw can be exploited after the CPU starts, requiring a high complexity adversary and no user interaction. Once the attack succeeds, it can raise the attacker’s privileges and produce a high integrity impact, while confidentiality and availability remain unaffected.

Affected Systems

The vulnerability impacts some Intel Xeon processors whose firmware contains the flawed input validation. Exact model or firmware versions were not disclosed, so any Xeon processor supplied by Intel whose firmware implements this logic could be affected.

Risk and Exploitability

The CVSS score of 4.0 indicates a moderate severity. With no EPSS data available, the likelihood of exploitation is unclear, and the vulnerability is not listed in CISA’s KEV catalog. It is presumed to be exploitable only in a local environment by an attacker who already has privileged access, making it a conditional risk that requires patching or mitigating controls by the system owner.

Generated by OpenCVE AI on August 12, 2026 at 12:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the processor firmware to the latest Intel release that addresses the input validation flaw.
  • If a firmware update is not immediately available, enforce strict local privilege controls to limit users who can execute firmware modifications.
  • Monitor for firmware integrity and verify that boot and firmware signing mechanisms are active to prevent unauthorized changes.

Generated by OpenCVE AI on August 12, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Title Firmware Input Validation Flaw Allows Privilege Escalation on Xeon Processors

Tue, 11 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 4, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T13:51:14.729Z

Reserved: 2025-12-09T04:00:18.785Z

Link: CVE-2026-20901

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T18:17:24.593

Modified: 2026-08-12T14:17:49.810

Link: CVE-2026-20901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T13:00:03Z

Weaknesses
  • CWE-20

    Improper Input Validation