CVE-2026-20783
Analyzed Analyzed - Analysis Complete

Improper Input Validation in Intel NPU Driver Firmware

Vulnerability report for CVE-2026-20783, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-31

Assigner: Intel Corporation

Description

Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-31
Generated
2026-09-01
AI Q&A
2026-08-11
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
intel neural_processing_unit_driver to 1.32.0 (exc)
intel neural_processing_unit_driver to 32.0.100.4723 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper conditions check in the firmware for the Intel NPU Driver. It allows a denial of service via local access by an unprivileged authenticated attacker with low complexity and no special internal knowledge. The attack requires no user interaction.

Detection Guidance

Detection requires checking for the presence of the Intel NPU Driver firmware versions within Ring 1. Review installed drivers and firmware versions using system management tools or Intel's provided utilities. No specific commands are provided in the context.

Impact Analysis

This vulnerability may cause a denial of service on the affected system. It could lead to system unavailability, though it does not directly impact confidentiality or integrity beyond minor integrity impact.

Compliance Impact

This vulnerability primarily impacts system availability due to potential denial of service. For GDPR, availability is a key principle, so repeated disruptions could affect compliance. HIPAA requires safeguards for data integrity and availability, which may be compromised if the system becomes unavailable. However, the vulnerability does not directly expose data, so confidentiality impacts are none.

Mitigation Strategies

Update the Intel NPU Driver firmware to the latest version provided by Intel. Apply security patches if available. Restrict local access to unprivileged users and monitor for unusual activity that may indicate exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20783. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart