CVE-2026-20898

HIGHCVSS 7.2/10EPSS 0.12%

Last modified

CVE-2026-20898 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. EPSS estimates a 0.12% chance of exploitation in the next 30 days.

Description

Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersions
IntelXeon 6315p FirmwareAll versions
IntelXeon 6325p FirmwareAll versions
IntelXeon 6333p FirmwareAll versions
IntelXeon 6337p FirmwareAll versions
IntelXeon 6349p FirmwareAll versions
IntelXeon 6353p FirmwareAll versions
IntelXeon 6357p FirmwareAll versions
IntelXeon 6369p FirmwareAll versions
IntelXeon 6377p FirmwareAll versions
IntelXeon 6503p FirmwareAll versions
IntelXeon 6503p-B FirmwareAll versions
IntelXeon 6505p FirmwareAll versions
IntelXeon 6507p FirmwareAll versions
IntelXeon 6511p FirmwareAll versions
IntelXeon 6513p-B FirmwareAll versions
IntelXeon 6515p FirmwareAll versions
IntelXeon 6516p-B FirmwareAll versions
IntelXeon 6517p FirmwareAll versions
IntelXeon 6518p-B FirmwareAll versions
IntelXeon 6520p FirmwareAll versions
IntelXeon 6521p FirmwareAll versions
IntelXeon 6523p-B FirmwareAll versions
IntelXeon 6527p FirmwareAll versions
IntelXeon 6530p FirmwareAll versions
IntelXeon 6532p-B FirmwareAll versions
IntelXeon 6533p-B FirmwareAll versions
IntelXeon 6543p-B FirmwareAll versions
IntelXeon 6544p-B FirmwareAll versions
IntelXeon 6546p-B FirmwareAll versions
IntelXeon 6548p-B FirmwareAll versions
IntelXeon 6553p-B FirmwareAll versions
IntelXeon 6556p-B FirmwareAll versions
IntelXeon 6563p-B FirmwareAll versions
IntelXeon 6706p-B FirmwareAll versions
IntelXeon 6710e FirmwareAll versions
IntelXeon 6714p FirmwareAll versions
IntelXeon 6716p-B FirmwareAll versions
IntelXeon 6718p-B FirmwareAll versions
IntelXeon 6724p FirmwareAll versions
IntelXeon 6725p FirmwareAll versions
IntelXeon 6726p-B FirmwareAll versions
IntelXeon 6728p FirmwareAll versions
IntelXeon 6730p FirmwareAll versions
IntelXeon 6731e FirmwareAll versions
IntelXeon 6731p FirmwareAll versions
IntelXeon Silver 4410t FirmwareAll versions
IntelXeon Silver 4410tm FirmwareAll versions
IntelXeon Silver 4410y FirmwareAll versions
IntelXeon Silver 4416 FirmwareAll versions
IntelXeon Silver 4416\+ FirmwareAll versions

Showing 50 of 175 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-20898?
Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.
How severe is CVE-2026-20898?
CVE-2026-20898 has a CVSS score of 7.2/10 (HIGH severity). The EPSS model estimates a 0.12% probability of exploitation in the next 30 days.
How do I fix CVE-2026-20898?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-20898?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST