CVE-2026-20901
Last modified
CVE-2026-20901 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Xeon Bronze 3408u Firmware | All versions |
| Intel | Xeon Gold 5403n Firmware | All versions |
| Intel | Xeon Gold 5411n Firmware | All versions |
| Intel | Xeon Gold 5412u Firmware | All versions |
| Intel | Xeon Gold 5415\+ Firmware | All versions |
| Intel | Xeon Platinum 8592\+ Firmware | All versions |
| Intel | Xeon Platinum 8592v Firmware | All versions |
| Intel | Xeon Platinum 8593q Firmware | All versions |
| Intel | Xeon Silver 4509y Firmware | All versions |
| Intel | Xeon Silver 4510 Firmware | All versions |
| Intel | Xeon Silver 4510t Firmware | All versions |
| Intel | Xeon Silver 4514y Firmware | All versions |
| Intel | Xeon Silver 4516y\+ Firmware | All versions |
| Intel | Xeon Gold 5416s Firmware | All versions |
| Intel | Xeon Gold 5418n Firmware | All versions |
| Intel | Xeon Gold 5418y Firmware | All versions |
| Intel | Xeon Gold 5420\+ Firmware | All versions |
| Intel | Xeon Gold 5423n Firmware | All versions |
| Intel | Xeon Gold 5433n Firmware | All versions |
| Intel | Xeon Gold 6403n Firmware | All versions |
| Intel | Xeon Gold 6414u Firmware | All versions |
| Intel | Xeon Gold 6416h Firmware | All versions |
| Intel | Xeon Gold 6418h Firmware | All versions |
| Intel | Xeon Gold 6421n Firmware | All versions |
| Intel | Xeon Gold 6423n Firmware | All versions |
| Intel | Xeon Gold 6426y Firmware | All versions |
| Intel | Xeon Gold 6428n Firmware | All versions |
| Intel | Xeon Gold 6430 Firmware | All versions |
| Intel | Xeon Gold 6433n Firmware | All versions |
| Intel | Xeon Gold 6433ne Firmware | All versions |
| Intel | Xeon Gold 6434 Firmware | All versions |
| Intel | Xeon Gold 6434h Firmware | All versions |
| Intel | Xeon Gold 6438m Firmware | All versions |
| Intel | Xeon Gold 6438n Firmware | All versions |
| Intel | Xeon Gold 6438y\+ Firmware | All versions |
| Intel | Xeon Gold 6442y Firmware | All versions |
| Intel | Xeon Gold 6443n Firmware | All versions |
| Intel | Xeon Gold 6444y Firmware | All versions |
| Intel | Xeon Gold 6448h Firmware | All versions |
| Intel | Xeon Gold 6448y Firmware | All versions |
| Intel | Xeon Gold 6454s Firmware | All versions |
| Intel | Xeon Gold 6458q Firmware | All versions |
| Intel | Xeon Platinum 8444h Firmware | All versions |
| Intel | Xeon Platinum 8450h Firmware | All versions |
| Intel | Xeon Platinum 8452y Firmware | All versions |
| Intel | Xeon Platinum 8454h Firmware | All versions |
| Intel | Xeon Platinum 8458p Firmware | All versions |
| Intel | Xeon Platinum 8460h Firmware | All versions |
| Intel | Xeon Platinum 8460y\+ Firmware | All versions |
| Intel | Xeon Platinum 8461v Firmware | All versions |
Showing 50 of 141 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-20901?
How severe is CVE-2026-20901?
How do I fix CVE-2026-20901?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-20894Cross-site scripting vulnerability exists in multiple Networ…4.8
- CVE-2026-20895The WebSocket backend uses charging station identifiers to u…7.5
- CVE-2026-20896Gitea Docker image versions up to and including 1.26.2 use R…9.8
- CVE-2026-20897Gitea does not properly validate repository ownership when d…9.1
- CVE-2026-20898Improper access control in the firmware for some in Alias Ch…7.2
- CVE-2026-2090A vulnerability was determined in SourceCodester Online Clas…9.8
- CVE-2026-20902An OS command injection vulnerability exists in XWEB Pro…8.8
- CVE-2026-20903Protection mechanism failure for some Intel(R) AI Containers…5.4
- CVE-2026-20904Gitea does not properly validate ownership when toggling Ope…6.5
- CVE-2026-20905Improper input validation for some Intel(R) QAT software dri…6.6
- CVE-2026-20906Protection mechanism failure for some Intel(R) Neural Compre…5.4
- CVE-2026-20908Time-of-check time-of-use race condition for the Intel(R) NP…5.8
Are you affected by CVE-2026-20901?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
