CVE-2026-20901: Input Validation
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20901?
CVE-2026-20901 has a risk score of 38, indicating a potential for significant impact.
How do I fix CVE-2026-20901?
To mitigate CVE-2026-20901, users should update their Intel Xeon processors firmware to the latest version provided by Intel.
What type of attack is associated with CVE-2026-20901?
CVE-2026-20901 is associated with a high complexity attack that may enable data alteration through improper input validation.
What is the potential impact of CVE-2026-20901?
The potential impact of CVE-2026-20901 includes escalation of privilege, which may allow an adversary to alter data.
Who is affected by CVE-2026-20901?
CVE-2026-20901 affects systems utilizing specific Intel Xeon processors firmware.