CVE-2026-20709 involves the use of default cryptographic keys in Intel Pentium Silver, Celeron J Series, and Celeron N Series processors, which could allow privileged attackers to escalate privileges on affected systems. The vulnerability requires physical hardware access combined with special internal knowledge and a privileged user account, making real-world exploitation highly constrained. The vulnerability carries a CVSS score of 6.6 (Medium severity) with a physical attack vector and high complexity requirements. While the confidentiality impact is rated high, the attack necessitates a privileged user and hardware reverse engineering expertise. The EPSS score of 0.00017 indicates minimal likelihood of exploitation compared to other known vulnerabilities. There is no evidence of active exploitation in the wild. The vulnerability is not included in CISA's Known Exploited Vulnerabilities catalog and is classified as inactive on security hotlists. No publicly available exploit code has been identified, and community attention remains minimal given the substantial barriers to practical exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series May Allow An Escalation Of Privilege. Hardware Reverse Engineer Adversary With A Privileged User Combined With A High Complexity Attack May Enable Escalation Of Privilege. This Result May Potentially Occur Via Physical Access When Attack Requirements Are Present With Special Internal Knowledge And Requires No User Interaction. The Potential Vulnerability May Impact The Confidentiality (High), Integrity (None) And Availability (None) Of The Vulnerable System, Resulting In Subsequent System Confidentiality (High), Integrity (High) And Availability (None) Impacts. | See referencesCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.