CVE-2026-33197
Last modified
CVE-2026-33197 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability..
Description
AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| AMI | AptioV | >= AptioV_5.0, < AptioV_5.044 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-33197?
How severe is CVE-2026-33197?
How do I fix CVE-2026-33197?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33190CoreDNS is a DNS server that chains plugins. In versions pri…7.5
- CVE-2026-33191Free5GC is an open-source Linux Foundation project for 5th g…8.6
- CVE-2026-33192Free5GC is an open-source Linux Foundation project for 5th g…5.3
- CVE-2026-33193Docmost is open-source collaborative wiki and documentation …4.6
- CVE-2026-33194SiYuan is a personal knowledge management system. Prior to v…6.8
- CVE-2026-33195Active Storage allows users to attach cloud and local files …9.8
- CVE-2026-3320Reflected Cross-Site Scripting (XSS) in the latest demo vers…5.1
- CVE-2026-33201Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., L…7
- CVE-2026-33202Active Storage allows users to attach cloud and local files …9.1
- CVE-2026-33203SiYuan is a personal knowledge management system. Prior to v…7.5
- CVE-2026-33204SimpleJWT is a simple JSON web token library written in PHP.…7.5
- CVE-2026-33205calibre is a cross-platform e-book manager for viewing, conv…5.5
Are you affected by CVE-2026-33197?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
