Skip to content
IntelCVE-2026-20885

Intel platforms: improper authentication

High7.0CVE-2026-20885 · Published Aug 11, 2026 · updated Aug 31, 2026

Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.

Intel advisory

Affected versions

PackageAffectedFixed in
Intel(R) platforms
Product
<= See referencesNo fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-287

More Intel advisories

All Intel
Advisory
Intel reference platforms: information disclosure
Medium4.0Aug 11
Intel Xeon processors: improper input validation
Medium4.0Aug 11
Intel Processors: information disclosure
Medium4.0Aug 11
Intel Extension for PyTorch: unsafe deserialization
Medium4.6Aug 11
Intel Transfer Learning Tool: privilege escalation
Medium6.3Aug 11
Intel Slim Bootloader may allow an information disclosure. S: integer overflow
Low2.4Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.