Vulnerability Description
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Xeon Bronze 3408U Firmware | - |
| Intel | Xeon Bronze 3408U | - |
| Intel | Xeon Gold 5403N Firmware | - |
| Intel | Xeon Gold 5403N | - |
| Intel | Xeon Gold 5411N Firmware | - |
| Intel | Xeon Gold 5411N | - |
| Intel | Xeon Gold 5412U Firmware | - |
| Intel | Xeon Gold 5412U | - |
| Intel | Xeon Gold 5415\+ Firmware | - |
| Intel | Xeon Gold 5415\+ | - |
| Intel | Xeon Platinum 8592\+ Firmware | - |
| Intel | Xeon Platinum 8592\+ | - |
| Intel | Xeon Platinum 8592V Firmware | - |
| Intel | Xeon Platinum 8592V | - |
| Intel | Xeon Platinum 8593Q Firmware | - |
| Intel | Xeon Platinum 8593Q | - |
| Intel | Xeon Silver 4509Y Firmware | - |
| Intel | Xeon Silver 4509Y | - |
| Intel | Xeon Silver 4510 Firmware | - |
| Intel | Xeon Silver 4510 | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-20901?
CVE-2026-20901 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexi...
How severe is CVE-2026-20901?
CVE-2026-20901 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-20901?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Xeon Bronze 3408U Firmware, Intel Xeon Bronze 3408U, Intel Xeon Gold 5403N Firmware, Intel Xeon Gold 5403N, Intel Xeon Gold 5411N Firmware.