CVE-2026-6485
Awaiting Analysis Awaiting Analysis - Queue

UEFI BIOS Shell Secure Boot Bypass

Vulnerability report for CVE-2026-6485, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: Insyde

Description

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
insyde insydeh2o to 8.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-489 The product is released with debugging code still enabled or active.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-6485 is a vulnerability in InsydeH2O UEFI BIOS versions up to 8.2 that allows bypassing Secure Boot protections. It can be exploited through the UEFI BIOS embedded Shell using shell commands or startup scripts.

Detection Guidance

Check if your system uses InsydeH2O UEFI BIOS versions up to 8.2 by inspecting BIOS version via system information tools or commands like 'wmic bios get smbiosbiosversion' on Windows or 'dmidecode -t bios' on Linux. Look for active debug code or unexpected shell access in BIOS settings or logs.

Impact Analysis

This vulnerability could allow attackers with local access to bypass Secure Boot, potentially leading to unauthorized system access, malware execution, or data theft. It impacts confidentiality, integrity, and availability of the system.

Compliance Impact

This vulnerability allows bypassing Secure Boot via UEFI BIOS embedded Shell, potentially enabling unauthorized access to system firmware and boot processes. Such bypasses could undermine security controls required by GDPR (data protection) and HIPAA (health data safeguards) by allowing attackers to install persistent malware or exfiltrate sensitive data before the OS loads.

Mitigation Strategies

Update InsydeH2O UEFI BIOS to the latest kernel versions (5.2B.17, 5.3A.17, 5.48.17, 5.56.17, 5.63.17, or 5.72.17) provided by Insyde. Disable the UEFI BIOS embedded Shell if not required and review startup scripts for unauthorized commands.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6485. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart