Boot Parameter Injection Vulnerability in IGEL OS by IGEL Technology
CVE-2026-82017
Key Information:
- Vendor
Igel
- Status
- Vendor
- CVE Published:
- 28 August 2026
Badges
What is CVE-2026-82017?
The IGEL OS versions prior to 12.7.6 and 11.11.150 are susceptible to a boot parameter injection vulnerability. This vulnerability can be exploited by attackers who have physical access to the device, enabling them to inject malicious Linux loader parameters. This is achieved by modifying an unencrypted and unsigned configuration area that the signed bootloader reads, allowing unauthorized command line parameters to be executed with elevated privileges. Importantly, this attack does not compromise measured boot integrity since it does not alter the boot code that triggers TPM PCR measurement failures.
Affected Version(s)
IGEL OS 11 11.0.0
IGEL OS 12 12.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
