CVE-2026-20728: Medium severity Intel Extension for TensorFlow vulnerability
Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Intel Extension for TensorFlowto a version that resolves this vulnerability.Fixed in 2.15.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20728?
CVE-2026-20728 has a risk score of 46, indicating a moderate severity vulnerability.
How do I fix CVE-2026-20728?
To mitigate CVE-2026-20728, update the Intel Extension for TensorFlow software to version 2.15.0.3 or later.
What type of vulnerability is CVE-2026-20728?
CVE-2026-20728 is categorized as a protection mechanism failure which can lead to escalation of privilege.
Who is affected by CVE-2026-20728?
CVE-2026-20728 affects users of the Intel Extension for TensorFlow software prior to version 2.15.0.3.
What conditions are required for CVE-2026-20728 to be exploited?
CVE-2026-20728 requires a system adversary to have a privileged user access and utilize a low complexity attack to exploit the vulnerability.