CVE-2026-20913
Analyzed Analyzed - Analysis Complete

Improper Input Validation in Intel Neural Compressor

Vulnerability report for CVE-2026-20913, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-31

Assigner: Intel Corporation

Description

Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-31
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
intel neural_compressor to 3.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an improper input validation flaw in Intel Neural Compressor software before v3.7. It allows an authenticated local attacker with low complexity to escalate privileges without special knowledge or user interaction. The attack could impact system confidentiality, integrity, and availability with low impact.

Detection Guidance

This vulnerability involves improper input validation in Intel Neural Compressor software before v3.7. Detection requires checking the installed version of the software. Use commands like 'pip show neural-compressor' or 'conda list neural-compressor' to verify the version. If the version is below v3.7, the system is vulnerable.

Impact Analysis

An attacker could gain higher privileges on your system, potentially accessing sensitive data or modifying system settings. This could lead to unauthorized changes, data leaks, or system disruptions if exploited.

Compliance Impact

The vulnerability may impact confidentiality, integrity, and availability of the system, which could potentially lead to unauthorized access or data breaches. This could affect compliance with standards like GDPR or HIPAA if sensitive data is exposed or altered.

Mitigation Strategies

Update Intel Neural Compressor software to version v3.7 or later to address improper input validation. Ensure all systems using this software are patched promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20913. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart