CVE-2026-10588

A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.

Published: 2026-07-16 Last update: 2026-07-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2026-10588 is rated Low Risk (28.5/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.15%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2026-10588

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-07-17 0.15%

Full EPSS history (1 record total)

Common vulnerability scoring system (CVSS) metrics for CVE-2026-10588

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.7 4.0 MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Click to expand
Attack vector (AV:L)
Attacker needs local access on the target system.
Attack complexity (AC:L)
Exploitation conditions are straightforward and stable.
Attack requirements (AT:N)
No additional preconditions are required beyond normal reachability.
Privileges required (PR:H)
High privileges are required.
User interaction (UI:N)
No user interaction is required.
Vulnerable system confidentiality impact (VC:H)
High confidentiality impact on the vulnerable system.
Vulnerable system integrity impact (VI:N)
No integrity impact on the vulnerable system.
Vulnerable system availability impact (VA:N)
No availability impact on the vulnerable system.
Subsequent system confidentiality impact (SC:N)
No confidentiality impact on subsequent systems.
Subsequent system integrity impact (SI:N)
No integrity impact on subsequent systems.
Subsequent system availability impact (SA:N)
No availability impact on subsequent systems.
Exploit maturity (threat) (E:X)
Not defined: no reliable threat intelligence; scoring assumes the worst case (equivalent to Attacked).
Confidentiality requirement (CR:X)
Not defined: insufficient information; scoring treats this like High (worst case).
Integrity requirement (IR:X)
Not defined: insufficient information; scoring treats this like High (worst case).
Availability requirement (AR:X)
Not defined: insufficient information; scoring treats this like High (worst case).
Modified attack vector (MAV:X)
Not defined: scoring uses the Base Attack Vector (AV).
Modified attack complexity (MAC:X)
Not defined: scoring uses the Base Attack Complexity (AC).
Modified attack requirements (MAT:X)
Not defined: scoring uses the Base Attack Requirements (AT).
Modified privileges required (MPR:X)
Not defined: scoring uses the Base Privileges Required (PR).
Modified user interaction (MUI:X)
Not defined: scoring uses the Base User Interaction (UI).
Modified vulnerable system confidentiality impact (MVC:X)
Not defined: scoring uses the Base VC metric.
Modified vulnerable system integrity impact (MVI:X)
Not defined: scoring uses the Base VI metric.
Modified vulnerable system availability impact (MVA:X)
Not defined: scoring uses the Base VA metric.
Modified subsequent system confidentiality impact (MSC:X)
Not defined: scoring uses the Base SC metric.
Modified subsequent system integrity impact (MSI:X)
Not defined: scoring uses the Base SI metric.
Modified subsequent system availability impact (MSA:X)
Not defined: scoring uses the Base SA metric.
Safety (supplemental) (S:X)
Not evaluated.
Automatable (supplemental) (AU:X)
Not evaluated.
Recovery (supplemental) (R:X)
Not evaluated.
Value density (supplemental) (V:X)
Not evaluated.
Vulnerability response effort (supplemental) (RE:X)
Not evaluated.
Provider urgency (supplemental) (U:X)
Not evaluated.
[email protected]
4.4 3.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:H)
They need powerful rights—admin, root, or similar—before this pays off.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
0.8 3.6 [email protected]

Weakness enumeration for CVE-2026-10588

GitHub Security Advisory for CVE-2026-10588

GHSA-vr8x-qg62-cfwr · Severity: medium — A potential vulnerability could allow a local privileged attacker to disclose the address of...

Affected software / configurations for CVE-2026-10588

Vendor Product Version Raw CPE
lenovo yoga_pro_7_15iph11_bios >= 0, < tncn37ww cpe:2.3:h:lenovo:yoga_pro_7_15iph11_bios:*:*:*:*:*:*:*:*
lenovo ideapad_pro_5_16iph11_bios >= 0, < s4cn62ww cpe:2.3:h:lenovo:ideapad_pro_5_16iph11_bios:*:*:*:*:*:*:*:*
lenovo legion_7_16agp11_bios >= 0, <= tpcn27ww cpe:2.3:h:lenovo:legion_7_16agp11_bios:*:*:*:*:*:*:*:*
lenovo ideapad_pro_5_16agp11_bios >= 0, <= t8cn19ww cpe:2.3:h:lenovo:ideapad_pro_5_16agp11_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_5_16adr10_bios >= 0, <= u5cn07ww cpe:2.3:h:lenovo:legion_pro_5_16adr10_bios:*:*:*:*:*:*:*:*
lenovo lenovo_v15_g6_arp_bios >= 0, <= tycn15ww cpe:2.3:h:lenovo:lenovo_v15_g6_arp_bios:*:*:*:*:*:*:*:*
lenovo loq_15arp10e_bios >= 0, < sucn18ww cpe:2.3:h:lenovo:loq_15arp10e_bios:*:*:*:*:*:*:*:*
lenovo yoga_book_9_14iah10_bios >= 0, <= qeme23ww cpe:2.3:h:lenovo:yoga_book_9_14iah10_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_7_16afr10h_bios >= 0, < smcn20ww cpe:2.3:h:lenovo:legion_pro_7_16afr10h_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_5_16afr10_bios >= 0, <= recn14ww cpe:2.3:h:lenovo:legion_pro_5_16afr10_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_7_16adr10h_bios >= 0, < sjcn17ww cpe:2.3:h:lenovo:legion_pro_7_16adr10h_bios:*:*:*:*:*:*:*:*
lenovo lenovo_v15_g4_amn_bios >= 0, < l1cn72ww cpe:2.3:h:lenovo:lenovo_v15_g4_amn_bios:*:*:*:*:*:*:*:*
lenovo thinkbook_plus_g6_rollable_bios >= 0, <= qwcn34ww cpe:2.3:h:lenovo:thinkbook_plus_g6_rollable_bios:*:*:*:*:*:*:*:*
lenovo legion_5_15iax10_bios >= 0, <= s2cn15ww cpe:2.3:h:lenovo:legion_5_15iax10_bios:*:*:*:*:*:*:*:*
lenovo legion_5_15akp10_bios >= 0, <= rycn22ww cpe:2.3:h:lenovo:legion_5_15akp10_bios:*:*:*:*:*:*:*:*
lenovo legion_5_15irx10_bios >= 0, <= qncn28ww cpe:2.3:h:lenovo:legion_5_15irx10_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_5_16irx10_bios >= 0, <= s9cn13ww cpe:2.3:h:lenovo:legion_pro_5_16irx10_bios:*:*:*:*:*:*:*:*
lenovo thinkbook_16p_g6_adr_bios >= 0, < r7cn26ww cpe:2.3:h:lenovo:thinkbook_16p_g6_adr_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_5_16adr10_bios >= 0, <= rlcn21ww cpe:2.3:h:lenovo:legion_pro_5_16adr10_bios:*:*:*:*:*:*:*:*
lenovo legion_5_15ahp10_bios >= 0, < rgcn35ww cpe:2.3:h:lenovo:legion_5_15ahp10_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_7_16irx9h_bios >= 0, <= n2cn26ww cpe:2.3:h:lenovo:legion_pro_7_16irx9h_bios:*:*:*:*:*:*:*:*
lenovo legion_9_16irx9_bios >= 0, <= nxcn20ww cpe:2.3:h:lenovo:legion_9_16irx9_bios:*:*:*:*:*:*:*:*
lenovo ideapad_slim_3_16iru9_bios >= 0, < p2cn27ww cpe:2.3:h:lenovo:ideapad_slim_3_16iru9_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_5_16irx9_bios >= 0, < n0cn35ww cpe:2.3:h:lenovo:legion_pro_5_16irx9_bios:*:*:*:*:*:*:*:*
lenovo ideapad_pro_5_16imh9_bios >= 0, <= mecn68ww cpe:2.3:h:lenovo:ideapad_pro_5_16imh9_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_7_16arx8h_bios >= 0, <= lpcn45ww cpe:2.3:h:lenovo:legion_pro_7_16arx8h_bios:*:*:*:*:*:*:*:*
lenovo thinkbook_plus_g4_iru_bios >= 0, <= lucn47ww cpe:2.3:h:lenovo:thinkbook_plus_g4_iru_bios:*:*:*:*:*:*:*:*
lenovo legion_slim_5_14aph8_bios >= 0, <= macn33ww cpe:2.3:h:lenovo:legion_slim_5_14aph8_bios:*:*:*:*:*:*:*:*
lenovo thinkbook_plus_g5_tab_thinkbook_plus_g5_station_bios >= 0, <= p8cn42ww cpe:2.3:h:lenovo:thinkbook_plus_g5_tab_thinkbook_plus_g5_station_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_7_16arx8h_bios >= 0, <= lpcn59ww cpe:2.3:h:lenovo:legion_pro_7_16arx8h_bios:*:*:*:*:*:*:*:*
lenovo lenovo_v15_g4_iah_bios >= 0, < mccn39ww cpe:2.3:h:lenovo:lenovo_v15_g4_iah_bios:*:*:*:*:*:*:*:*
lenovo lenovo_v15_g5_irl_bios >= 0, < pmcn38ww cpe:2.3:h:lenovo:lenovo_v15_g5_irl_bios:*:*:*:*:*:*:*:*
lenovo yoga_pro_9_14irp8_bios >= 0, <= mbcn33ww cpe:2.3:h:lenovo:yoga_pro_9_14irp8_bios:*:*:*:*:*:*:*:*
lenovo ideapad_slim_3_16irh8_bios >= 0, < ltcn44ww cpe:2.3:h:lenovo:ideapad_slim_3_16irh8_bios:*:*:*:*:*:*:*:*
lenovo ideapad_pro_5_16irh8_bios >= 0, <= kzcn46ww cpe:2.3:h:lenovo:ideapad_pro_5_16irh8_bios:*:*:*:*:*:*:*:*
lenovo ideapad_slim_3_15amn8_bios >= 0, < l1cn51ww cpe:2.3:h:lenovo:ideapad_slim_3_15amn8_bios:*:*:*:*:*:*:*:*
lenovo yoga_9_14irp8_bios >= 0, < l4cn31ww cpe:2.3:h:lenovo:yoga_9_14irp8_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_5_16arx8_bios >= 0, <= lpcn59ww cpe:2.3:h:lenovo:legion_pro_5_16arx8_bios:*:*:*:*:*:*:*:*
lenovo lenovo_s14_g3_iap_bios >= 0, <= jkcn49ww cpe:2.3:h:lenovo:lenovo_s14_g3_iap_bios:*:*:*:*:*:*:*:*
lenovo ideapad_5_15aba7_bios >= 0, < kacn29ww cpe:2.3:h:lenovo:ideapad_5_15aba7_bios:*:*:*:*:*:*:*:*
lenovo thinkbook_16p_g5_irx_bios >= 0, < p5cn31ww cpe:2.3:h:lenovo:thinkbook_16p_g5_irx_bios:*:*:*:*:*:*:*:*
lenovo lenovo_v15_g2_ijl_laptop_bios >= 0, < htcn49ww cpe:2.3:h:lenovo:lenovo_v15_g2_ijl_laptop_bios:*:*:*:*:*:*:*:*
lenovo yoga_pro_9_16imh9_bios >= 0, <= nkcn30ww cpe:2.3:h:lenovo:yoga_pro_9_16imh9_bios:*:*:*:*:*:*:*:*
lenovo thinkbook_16p_g6_iax_bios >= 0, < r2cn57ww cpe:2.3:h:lenovo:thinkbook_16p_g6_iax_bios:*:*:*:*:*:*:*:*
lenovo legion_7_16iax10_bios >= 0, <= rxcn18ww cpe:2.3:h:lenovo:legion_7_16iax10_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_5_16iax10_bios >= 0, <= q6cn26ww cpe:2.3:h:lenovo:legion_pro_5_16iax10_bios:*:*:*:*:*:*:*:*
lenovo legion_pro_7_16iax10h_bios >= 0, <= q7cn31ww cpe:2.3:h:lenovo:legion_pro_7_16iax10h_bios:*:*:*:*:*:*:*:*
lenovo ideapad_slim_3_16irh10r_bios >= 0, <= qdcn23ww cpe:2.3:h:lenovo:ideapad_slim_3_16irh10r_bios:*:*:*:*:*:*:*:*
lenovo legion_5_15irx9_bios >= 0, <= ptcn14ww cpe:2.3:h:lenovo:legion_5_15irx9_bios:*:*:*:*:*:*:*:*
lenovo lenovo_v14_g6_itn_bios >= 0, < rhcn20ww cpe:2.3:h:lenovo:lenovo_v14_g6_itn_bios:*:*:*:*:*:*:*:*
lenovo yoga_book_9_14iah10_bios >= 0, <= qecn21ww cpe:2.3:h:lenovo:yoga_book_9_14iah10_bios:*:*:*:*:*:*:*:*
lenovo ideapad_slim_3_14itn9_bios >= 0, < qucn20ww cpe:2.3:h:lenovo:ideapad_slim_3_14itn9_bios:*:*:*:*:*:*:*:*
lenovo ideapad_slim_3_16arp10_bios >= 0, < qbcn30ww cpe:2.3:h:lenovo:ideapad_slim_3_16arp10_bios:*:*:*:*:*:*:*:*
lenovo ideapad_pro_5_16asp10_bios >= 0, <= r1cn24ww cpe:2.3:h:lenovo:ideapad_pro_5_16asp10_bios:*:*:*:*:*:*:*:*
lenovo legion_5_15aph9_bios >= 0, < pjcn18ww cpe:2.3:h:lenovo:legion_5_15aph9_bios:*:*:*:*:*:*:*:*
lenovo yoga_9_2-in-1_14ill10_bios >= 0, <= q9cn22ww cpe:2.3:h:lenovo:yoga_9_2-in-1_14ill10_bios:*:*:*:*:*:*:*:*
lenovo yoga_book_9_13imu9_bios >= 0, <= nvcn24ww cpe:2.3:h:lenovo:yoga_book_9_13imu9_bios:*:*:*:*:*:*:*:*
lenovo ideapad_pro_5_16iah10_bios >= 0, <= pzcn27ww cpe:2.3:h:lenovo:ideapad_pro_5_16iah10_bios:*:*:*:*:*:*:*:*
lenovo loq_15iax9e_bios >= 0, <= q8cn17ww cpe:2.3:h:lenovo:loq_15iax9e_bios:*:*:*:*:*:*:*:*
lenovo yoga_9_2-in-1_14imh9_bios >= 0, <= nncn31ww cpe:2.3:h:lenovo:yoga_9_2-in-1_14imh9_bios:*:*:*:*:*:*:*:*

References for CVE-2026-10588

cvelogic Threat Intelligence