CVE Vulnerabilities

CVE-2026-0438

Data Resource Access without Use of Connection Pooling

Published: May 15, 2026 | Modified: May 15, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker could, with active user interaction and under high complexity and present preconditions, trigger execution of attacker-controlled code in SMM, potentially compromising the system’s confidentiality, integrity, and availability.

Weakness

The product accesses a data resource through a database without using a connection pooling capability.

References