CVE-2026-6485 HIGH

CVE-2026-6485: UEFI BIOS embedded Shell can be used to bypass Secure Boot

Vendor Insyde Software
Product InsydeH2O
Weakness CWE-489
Published September 9, 2026
Last update September 9, 2026

CVSS base score

8.2/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

Key dates

02Disclosure timeline

September 9, 2026 CVE published