Boot Parameter Injection Vulnerability in IGEL OS by IGEL Technology
CVE-2026-82017

8.6HIGH

Key Information:

Vendor

Igel

Vendor
CVE Published:
28 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-82017?

The IGEL OS versions prior to 12.7.6 and 11.11.150 are susceptible to a boot parameter injection vulnerability. This vulnerability can be exploited by attackers who have physical access to the device, enabling them to inject malicious Linux loader parameters. This is achieved by modifying an unencrypted and unsigned configuration area that the signed bootloader reads, allowing unauthorized command line parameters to be executed with elevated privileges. Importantly, this attack does not compromise measured boot integrity since it does not alter the boot code that triggers TPM PCR measurement failures.

Affected Version(s)

IGEL OS 11 11.0.0

IGEL OS 12 12.0.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Darren McDonald from AmberWolf
.