AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-20713

MEDIUM · CVSS 4.5 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Certain firmware for Intel Xeon processors contains a flawed control flow implementation that could allow a privileged user to escalate their privileges through a complex local attack, which does not require user interaction. While the immediate impact on confidentiality, integrity, and availability of the system is minimal, successful exploitation could lead to significant risks to system confidentiality and integrity. Organizations using affected Intel Xeon processors should prioritize remediation efforts to mitigate potential privilege escalation threats.

CVE
CVE-2026-20713
Severity
MEDIUM
CVSS
4.5
EPSS
0.10%

Original NVD Description

Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.