CVE-2026-20712
Received Received - Intake

Incomplete Cleanup in Intel UEFI Firmware Allows Information Disclosure

Vulnerability report for CVE-2026-20712, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Intel Corporation

Description

Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
intel uefi_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-459 The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an incomplete cleanup issue in some UEFI firmware for Intel reference platforms. It may allow an information disclosure if exploited by a privileged local user with low complexity. The attack requires no special internal knowledge or user interaction.

Detection Guidance

This vulnerability involves UEFI firmware on Intel reference platforms. Detection requires checking firmware versions and configurations. Use system management tools like Intel's firmware update utility or BIOS/UEFI setup to inspect firmware versions. No specific commands are provided in the context.

Impact Analysis

An attacker with privileged access could exploit this to expose sensitive data. The impact is primarily on system confidentiality, which could be high, while integrity and availability remain unaffected.

Mitigation Strategies

Apply firmware updates from Intel to patch the UEFI cleanup issue. Ensure privileged user access is restricted and monitor for unauthorized local access attempts. No specific mitigation steps are detailed beyond firmware updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20712. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart