AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-20898

HIGH · CVSS 8.5 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Improper access control in the firmware of certain Intel Xeon processors may allow attackers to escalate privileges, particularly through local access methods that do not require user interaction. This vulnerability poses a high risk to system confidentiality and integrity, making it critical for organizations utilizing affected Intel processors to prioritize remediation efforts. System administrators and security teams should assess their environments for potential exposure and implement necessary mitigations.

CVE
CVE-2026-20898
Severity
HIGH
CVSS
8.5
EPSS
0.12%

Original NVD Description

Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.