CVE-2026-20898
Last modified
CVE-2026-20898 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Xeon 6315p Firmware | All versions |
| Intel | Xeon 6325p Firmware | All versions |
| Intel | Xeon 6333p Firmware | All versions |
| Intel | Xeon 6337p Firmware | All versions |
| Intel | Xeon 6349p Firmware | All versions |
| Intel | Xeon 6353p Firmware | All versions |
| Intel | Xeon 6357p Firmware | All versions |
| Intel | Xeon 6369p Firmware | All versions |
| Intel | Xeon 6377p Firmware | All versions |
| Intel | Xeon 6503p Firmware | All versions |
| Intel | Xeon 6503p-B Firmware | All versions |
| Intel | Xeon 6505p Firmware | All versions |
| Intel | Xeon 6507p Firmware | All versions |
| Intel | Xeon 6511p Firmware | All versions |
| Intel | Xeon 6513p-B Firmware | All versions |
| Intel | Xeon 6515p Firmware | All versions |
| Intel | Xeon 6516p-B Firmware | All versions |
| Intel | Xeon 6517p Firmware | All versions |
| Intel | Xeon 6518p-B Firmware | All versions |
| Intel | Xeon 6520p Firmware | All versions |
| Intel | Xeon 6521p Firmware | All versions |
| Intel | Xeon 6523p-B Firmware | All versions |
| Intel | Xeon 6527p Firmware | All versions |
| Intel | Xeon 6530p Firmware | All versions |
| Intel | Xeon 6532p-B Firmware | All versions |
| Intel | Xeon 6533p-B Firmware | All versions |
| Intel | Xeon 6543p-B Firmware | All versions |
| Intel | Xeon 6544p-B Firmware | All versions |
| Intel | Xeon 6546p-B Firmware | All versions |
| Intel | Xeon 6548p-B Firmware | All versions |
| Intel | Xeon 6553p-B Firmware | All versions |
| Intel | Xeon 6556p-B Firmware | All versions |
| Intel | Xeon 6563p-B Firmware | All versions |
| Intel | Xeon 6706p-B Firmware | All versions |
| Intel | Xeon 6710e Firmware | All versions |
| Intel | Xeon 6714p Firmware | All versions |
| Intel | Xeon 6716p-B Firmware | All versions |
| Intel | Xeon 6718p-B Firmware | All versions |
| Intel | Xeon 6724p Firmware | All versions |
| Intel | Xeon 6725p Firmware | All versions |
| Intel | Xeon 6726p-B Firmware | All versions |
| Intel | Xeon 6728p Firmware | All versions |
| Intel | Xeon 6730p Firmware | All versions |
| Intel | Xeon 6731e Firmware | All versions |
| Intel | Xeon 6731p Firmware | All versions |
| Intel | Xeon Silver 4410t Firmware | All versions |
| Intel | Xeon Silver 4410tm Firmware | All versions |
| Intel | Xeon Silver 4410y Firmware | All versions |
| Intel | Xeon Silver 4416 Firmware | All versions |
| Intel | Xeon Silver 4416\+ Firmware | All versions |
Showing 50 of 175 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-20898?
How severe is CVE-2026-20898?
How do I fix CVE-2026-20898?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-20892Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5…8.6
- CVE-2026-20893Origin validation error issue exists in Fujitsu Security Sol…8.5
- CVE-2026-20894Cross-site scripting vulnerability exists in multiple Networ…4.8
- CVE-2026-20895The WebSocket backend uses charging station identifiers to u…7.5
- CVE-2026-20896Gitea Docker image versions up to and including 1.26.2 use R…9.8
- CVE-2026-20897Gitea does not properly validate repository ownership when d…9.1
- CVE-2026-2090A vulnerability was determined in SourceCodester Online Clas…9.8
- CVE-2026-20901Improper input validation for some Intel(R) Xeon(R) processo…5.3
- CVE-2026-20902An OS command injection vulnerability exists in XWEB Pro…8.8
- CVE-2026-20903Protection mechanism failure for some Intel(R) AI Containers…5.4
- CVE-2026-20904Gitea does not properly validate ownership when toggling Ope…6.5
- CVE-2026-20905Improper input validation for some Intel(R) QAT software dri…6.6
Are you affected by CVE-2026-20898?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
