---
id: CVE-2026-33197
title: "AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed\_Inputs” by local access"
summary: "AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed\_Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact\_syste…"
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'
cwe:
  - CWE-184
vendor: AMI
product: AptioV
affected:
  - AptioV >= AptioV_5.0 < AptioV_5.044
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T16:18:08.077'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33197'
references:
  - url: 'https://go.ami.com/hubfs/Security%20Advisories/2026/AMI-SA-2026001.pdf'
    label: biossecurity@ami.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-08T15:22:22.910278Z'
cvssSource: cna
ingestedAt: '2026-09-08T15:33:26.985Z'
epss: 0.00122
epssPercentile: 0.02305
---

## Overview

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
