A vulnerability has been found in Insyde H2O and classified as very critical. Affected by this issue is some unknown functionality of the component Verified Boot. The manipulation leads to improper authentication.
This vulnerability is referenced as CVE-2026-6484. The attack can only be performed from a local environment. No exploit is available.