Description
Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper input validation flaw exists in Intel Neural Compressor software versions prior to 3.7 that allows an authenticated user who is normally unprivileged to elevate their privileges locally. The vulnerability stems from failing to validate certain user-supplied data in Ring 3, enabling a limited privilege escalation. The potential compromise of confidentiality and integrity is considered low, and no additional availability impact beyond the initial privilege gain is expected.

Affected Systems

Intel’s Neural Compressor software, used for accelerating machine learning inference, is affected in all releases before version 3.7. The flaw applies to any installation executed under a local user account, presenting a risk to systems that rely on earlier builds.

Risk and Exploitability

With a CVSS score of 4.8, the flaw is of moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, and it requires local access and an authenticated session, yet the attack complexity is low and no special internal knowledge is needed. Overall risk remains low, though mitigations are recommended.

Generated by OpenCVE AI on August 12, 2026 at 21:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Intel Neural Compressor to version 3.7 or later, which addresses the improper input validation flaw.
  • If an upgrade is not yet available, limit execution of the Neural Compressor binary to privileged accounts only, preventing unprivileged users from invoking it.
  • Review any custom integration scripts that pass user input to the Neural Compressor and add robust validation checks to enforce correct data formats.

Generated by OpenCVE AI on August 12, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Intel neural Compressor
CPEs cpe:2.3:a:intel:neural_compressor:*:*:*:*:*:python:*:*
Vendors & Products Intel neural Compressor
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel neural Compressor Software
Vendors & Products Intel
Intel neural Compressor Software

Thu, 13 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Input Validation in Intel Neural Compressor

Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Intel Neural Compressor Neural Compressor Software
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T15:30:13.619Z

Reserved: 2025-12-19T04:00:14.893Z

Link: CVE-2026-20913

cve-icon Vulnrichment

Updated: 2026-08-12T15:30:08.870Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:17:54.887

Modified: 2026-08-31T14:07:17.210

Link: CVE-2026-20913

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses
  • CWE-20

    Improper Input Validation