Junglewise Threat Intelligence

CVE-2026-20906: Intel Neural Compressor protection mechanism failure

CVE-2026-20906 · Severity: info · CVSS 5.4 · Published 2026-08-11

Vendors: Intel.

Executive brief

Intel Neural Compressor is a software tool used to optimize machine learning models for deployment. A protection mechanism failure in versions before 3.6 allows an unprivileged user to escalate privileges to gain control of the system, potentially compromising confidentiality, integrity, and availability of the system and any data it processes.

Technical details

This vulnerability is a protection mechanism failure affecting Intel Neural Compressor software before version 3.6, operating within Ring 3 (user-mode applications). The vulnerability allows unprivileged software with a privileged user to escalate privileges through a low-complexity local attack requiring passive user interaction. An attacker can achieve escalation of privilege, potentially impacting system confidentiality, integrity, and availability. Intel recommends updating to version 3.7 or later, with patches available at the official GitHub releases repository.

Affected products

  • Intel Neural Compressor before v3.7

Timeline

  • 2026-08-11: disclosed

References

Related threats