CVE-2026-20708
Awaiting Analysis Awaiting Analysis - Queue

Information Disclosure in Intel AMT and Standard Manageability

Vulnerability report for CVE-2026-20708, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: Intel Corporation

Description

Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-11
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
intel amt *
intel standard_manageability *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves sensitive information being inserted into log files in Intel(R) AMT and Intel(R) Standard Manageability. A network adversary with privileged access could exploit it to disclose data through a high-complexity attack. The attack requires no user interaction and no special internal knowledge beyond network access.

Detection Guidance

This vulnerability involves sensitive information exposure in logs for Intel AMT and Intel Standard Manageability. Detection requires checking logs for unauthorized data insertion, particularly in Intel management interfaces. Monitor logs for unusual entries in Intel AMT or Standard Manageability logs, especially those containing privileged user activity or network access patterns.

Impact Analysis

This vulnerability may lead to unauthorized data exposure, compromising the confidentiality of sensitive information. It does not directly affect system integrity or availability but could result in high confidentiality impacts on the vulnerable system.

Compliance Impact

This vulnerability may lead to unauthorized disclosure of sensitive information through log files, which could violate confidentiality requirements in standards like GDPR and HIPAA. Unauthorized data exposure risks non-compliance with privacy regulations that mandate strict protection of personal or health data.

Mitigation Strategies

Apply vendor-provided security updates or patches for Intel AMT and Intel Standard Manageability. Disable or restrict network access to these components if not required. Monitor logs for suspicious activity related to privileged user access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20708. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart