CVE-2026-20716
Analyzed Analyzed - Analysis Complete

Improper Access Control in Intel Processors

Vulnerability report for CVE-2026-20716, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-31

Assigner: Intel Corporation

Description

Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-31
Generated
2026-09-01
AI Q&A
2026-08-11
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 90 associated CPEs
Vendor Product Version / Range
intel xeon_634_firmware *
intel xeon_636_firmware *
intel xeon_638_firmware *
intel xeon_654_firmware *
intel xeon_656_firmware *
intel xeon_658x_firmware *
intel xeon_674x_firmware *
intel xeon_676x_firmware *
intel xeon_678x_firmware *
intel xeon_696x_firmware *
intel xeon_698x_firmware *
intel xeon_6315p_firmware *
intel xeon_6325p_firmware *
intel xeon_6333p_firmware *
intel xeon_6337p_firmware *
intel xeon_6349p_firmware *
intel xeon_6353p_firmware *
intel xeon_6357p_firmware *
intel xeon_6369p_firmware *
intel xeon_6377p_firmware *
intel xeon_6503p_firmware *
intel xeon_6503p-b_firmware *
intel xeon_6505p_firmware *
intel xeon_6507p_firmware *
intel xeon_6511p_firmware *
intel xeon_6513p-b_firmware *
intel xeon_6515p_firmware *
intel xeon_6516p-b_firmware *
intel xeon_6517p_firmware *
intel xeon_6518p-b_firmware *
intel xeon_6520p_firmware *
intel xeon_6521p_firmware *
intel xeon_6523p-b_firmware *
intel xeon_6527p_firmware *
intel xeon_6530p_firmware *
intel xeon_6532p-b_firmware *
intel xeon_6533p-b_firmware *
intel xeon_6543p-b_firmware *
intel xeon_6544p-b_firmware *
intel xeon_6546p-b_firmware *
intel xeon_6548p-b_firmware *
intel xeon_6553p-b_firmware *
intel xeon_6556p-b_firmware *
intel xeon_6563p-b_firmware *
intel xeon_6706p-b_firmware *
intel xeon_6710e_firmware *
intel xeon_6714p_firmware *
intel xeon_6716p-b_firmware *
intel xeon_6718p-b_firmware *
intel xeon_6724p_firmware *
intel xeon_6725p_firmware *
intel xeon_6726p-b_firmware *
intel xeon_6728p_firmware *
intel xeon_6730p_firmware *
intel xeon_6731e_firmware *
intel xeon_6731p_firmware *
intel xeon_6732p_firmware *
intel xeon_6736p_firmware *
intel xeon_6737p_firmware *
intel xeon_6738p_firmware *
intel xeon_6740e_firmware *
intel xeon_6740p_firmware *
intel xeon_6741p_firmware *
intel xeon_6745p_firmware *
intel xeon_6746e_firmware *
intel xeon_6747p_firmware *
intel xeon_6748p_firmware *
intel xeon_6756e_firmware *
intel xeon_6756p-b_firmware *
intel xeon_6760p_firmware *
intel xeon_6761p_firmware *
intel xeon_6766e_firmware *
intel xeon_6766p-b_firmware *
intel xeon_6767p_firmware *
intel xeon_6768p_firmware *
intel xeon_6768p-b_firmware *
intel xeon_6774p_firmware *
intel xeon_6776p_firmware *
intel xeon_6776p-b_firmware *
intel xeon_6780e_firmware *
intel xeon_6781p_firmware *
intel xeon_6787p_firmware *
intel xeon_6788p_firmware *
intel xeon_6944p_firmware *
intel xeon_6952p_firmware *
intel xeon_6960p_firmware *
intel xeon_6962p_firmware *
intel xeon_6972p_firmware *
intel xeon_6978p_firmware *
intel xeon_6979p_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an improper access control vulnerability in some Intel processors where user applications may escalate privileges. It requires a local attack with authenticated user access, special internal knowledge, and high complexity. The attack could impact system confidentiality and integrity but does not affect availability.

Detection Guidance

This vulnerability requires specialized hardware knowledge and local access to exploit. Detection may involve monitoring for unusual privilege escalation patterns or unauthorized system modifications. No specific commands are provided in the context.

Impact Analysis

An attacker could gain elevated privileges on your system, potentially accessing sensitive data or modifying system settings. This requires local access and specific conditions, making it difficult but not impossible to exploit.

Compliance Impact

This vulnerability may impact confidentiality and integrity of systems, which could lead to unauthorized access or data breaches. Such incidents could potentially violate compliance requirements under standards like GDPR or HIPAA, depending on the data involved and the organization's specific obligations.

Mitigation Strategies

Apply Intel's official microcode updates or firmware patches as soon as they are available. Monitor Intel's security advisories for updates. Ensure least-privilege access controls are enforced on systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20716. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart