CVE-2026-20901

MEDIUMCVSS 5.3/10EPSS 0.10%

Last modified

CVE-2026-20901 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. EPSS estimates a 0.10% chance of exploitation in the next 30 days.

Description

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersions
IntelXeon Bronze 3408u FirmwareAll versions
IntelXeon Gold 5403n FirmwareAll versions
IntelXeon Gold 5411n FirmwareAll versions
IntelXeon Gold 5412u FirmwareAll versions
IntelXeon Gold 5415\+ FirmwareAll versions
IntelXeon Platinum 8592\+ FirmwareAll versions
IntelXeon Platinum 8592v FirmwareAll versions
IntelXeon Platinum 8593q FirmwareAll versions
IntelXeon Silver 4509y FirmwareAll versions
IntelXeon Silver 4510 FirmwareAll versions
IntelXeon Silver 4510t FirmwareAll versions
IntelXeon Silver 4514y FirmwareAll versions
IntelXeon Silver 4516y\+ FirmwareAll versions
IntelXeon Gold 5416s FirmwareAll versions
IntelXeon Gold 5418n FirmwareAll versions
IntelXeon Gold 5418y FirmwareAll versions
IntelXeon Gold 5420\+ FirmwareAll versions
IntelXeon Gold 5423n FirmwareAll versions
IntelXeon Gold 5433n FirmwareAll versions
IntelXeon Gold 6403n FirmwareAll versions
IntelXeon Gold 6414u FirmwareAll versions
IntelXeon Gold 6416h FirmwareAll versions
IntelXeon Gold 6418h FirmwareAll versions
IntelXeon Gold 6421n FirmwareAll versions
IntelXeon Gold 6423n FirmwareAll versions
IntelXeon Gold 6426y FirmwareAll versions
IntelXeon Gold 6428n FirmwareAll versions
IntelXeon Gold 6430 FirmwareAll versions
IntelXeon Gold 6433n FirmwareAll versions
IntelXeon Gold 6433ne FirmwareAll versions
IntelXeon Gold 6434 FirmwareAll versions
IntelXeon Gold 6434h FirmwareAll versions
IntelXeon Gold 6438m FirmwareAll versions
IntelXeon Gold 6438n FirmwareAll versions
IntelXeon Gold 6438y\+ FirmwareAll versions
IntelXeon Gold 6442y FirmwareAll versions
IntelXeon Gold 6443n FirmwareAll versions
IntelXeon Gold 6444y FirmwareAll versions
IntelXeon Gold 6448h FirmwareAll versions
IntelXeon Gold 6448y FirmwareAll versions
IntelXeon Gold 6454s FirmwareAll versions
IntelXeon Gold 6458q FirmwareAll versions
IntelXeon Platinum 8444h FirmwareAll versions
IntelXeon Platinum 8450h FirmwareAll versions
IntelXeon Platinum 8452y FirmwareAll versions
IntelXeon Platinum 8454h FirmwareAll versions
IntelXeon Platinum 8458p FirmwareAll versions
IntelXeon Platinum 8460h FirmwareAll versions
IntelXeon Platinum 8460y\+ FirmwareAll versions
IntelXeon Platinum 8461v FirmwareAll versions

Showing 50 of 141 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-20901?
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.
How severe is CVE-2026-20901?
CVE-2026-20901 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.10% probability of exploitation in the next 30 days.
How do I fix CVE-2026-20901?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-20901?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST