Junglewise Threat Intelligence

CVE-2026-6485: Insyde InsydeH2O Secure Boot bypass via embedded shell

CVE-2026-6485 · Severity: high · CVSS 8.2 · Published 2026-09-09

Technologies: InsydeH2O. Vendors: Insyde.

Executive brief

Insyde's InsydeH2O is UEFI firmware used across many laptop and desktop computers. A vulnerability in the embedded shell allows a privileged local attacker to bypass Secure Boot protections, potentially enabling malicious code to run at the lowest system level before the operating system loads. This could allow unauthorized access to sensitive data or complete system compromise.

Technical details

The vulnerability exists in the UEFI BIOS embedded shell component, where active debug code (CWE-489) allows shell commands and startup scripts to bypass Secure Boot verification. The attack requires high-level privilege (firmware/BIOS access) and local system access, with no user interaction needed. An attacker with these privileges can execute arbitrary UEFI shell commands to disable or circumvent Secure Boot mechanisms, enabling persistent code execution at boot time before OS security controls take effect. Patches are available across all affected Kernel versions (5.2 through 5.7) with specific patched versions identified by Insyde.

Affected products

  • Insyde InsydeH2O Kernel 5.2 before 05.2B.17, Kernel 5.3 before 05.3A.17, Kernel 5.4 before 05.48.17, Kernel 5.5 before 05.56.17, Kernel 5.6 before 05.63.17, Kernel 5.7 before 05.72.17

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Patches released for all affected kernel versions

References

Related threats