CVE-2026-8810: HDD Password leakage vulnerability
Published Aug 19, 2026
·Updated
On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
Event History
Aug 19, 2026
CVE Published
via MITRE·06:03 AM
Data Sourced
via MITRE·06:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What attacker access and conditions are indicated by the CVSS vector?
The vector indicates physical access, low privileges, required user interaction, and high attack complexity. It also indicates that successful exploitation can affect resources beyond the initially vulnerable security authority.
2
Which systems are in scope?
The issue is described as affecting ARM platforms where the HDD Password architecture design allows retrieval of the password from UEFI variables.
3
What is the potential impact after exploitation?
The CVSS vector rates confidentiality, integrity, and availability impact as high. The described direct result is disclosure of the HDD Password from UEFI variables.