Junglewise Threat Intelligence

CVE-2026-20708: Intel AMT and Standard Manageability sensitive information in log file

CVE-2026-20708 · Severity: info · CVSS 5.9 · Published 2026-08-11

Technologies: Intel Active Management Technology (AMT), Intel Standard Manageability. Vendors: Intel.

Executive brief

Intel Active Management Technology (AMT) and Standard Manageability are firmware-based remote management systems built into Intel chipsets and processors. This vulnerability allows insertion of sensitive information into log files, enabling an attacker with privileged network access to extract confidential data. An exploit could expose credentials, authentication tokens, or other sensitive operational details stored in system logs, compromising the security of managed systems across enterprises.

Technical details

The vulnerability is classified as insertion of sensitive information into a log file (CWE-532) in Intel AMT and Standard Manageability firmware. An attacker with network access and elevated privileges can exploit a high-complexity attack path to extract confidential information from log files, causing information disclosure with high impact to confidentiality. The attack does not require user interaction and affects the firmware subsystem across multiple Intel chipset and processor families. Patches are available as firmware updates; affected users should update to versions 11.13.6, 11.23.6, 11.9.6, 12.1.5, 14.1.80, 15.0.56, or later depending on their platform.

Affected products

  • Intel Active Management Technology (AMT) Before 11.13.6, 11.23.6, 11.9.6, 12.1.5, 14.1.80, 15.0.56 (platform-dependent)
  • Intel Standard Manageability Before 11.13.6, 11.23.6, 11.9.6, 12.1.5, 14.1.80, 15.0.56 (platform-dependent)

Timeline

  • 2026-08-11: disclosed: Intel advisory INTEL-SA-01427 released

References

Related threats