CVE-2026-8810

Summary

On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.

Affected Software

VendorProductVersion RangeStatus
Insyde SoftwareInsydeH2O, InsydeH2O ARMKernel 5.6 < 05.63.21affected
Insyde SoftwareInsydeH2O, InsydeH2O ARMKernel 5.7 < 05.72.21affected

Weaknesses

  • CWE-522: CWE-522: Insufficiently Protected Credentials

References