CVE-2026-20705
Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
- EPSS probability
- 0.10%
- CWE
- CWE-922
- Published
- 2026-08-11
- Last modified
- 2026-08-12
Affected products
- n/a Intel(R) platform
Weakness type
Related vulnerabilities
- CVE-2026-44629 — Improper access control to the Synergis Softwire installation folder. This vulnerability affects...
- CVE-2026-47362 — The Datadog Android application stores operationally sensitive content in plaintext SQLite...
- CVE-2026-46511 — HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
- CVE-2025-32751 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information...
- CVE-2025-32746 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information...
- CVE-2026-7257 — ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the...
- CVE-2026-40868 — kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
- CVE-2026-26152 — Microsoft Cryptographic Services Elevation of Privilege Vulnerability