Secure Boot Bypass in IGEL OS Products by IGEL Technology
CVE-2026-82018
6.8MEDIUM
What is CVE-2026-82018?
The vulnerability allows physically present attackers to gain unauthorized root access to the affected IGEL OS versions by exploiting a flaw in the GRUB boot stage. By placing an unsigned empty file named igel.conf on a partition, attackers can circumvent the secure boot mechanism, leveraging a fail-open signature verification behavior of GRUB. This enables them to enter an interactive GRUB prompt and subsequently boot the device's own kernel with custom command-line arguments, ultimately gaining root access while maintaining the integrity of TPM PCR values.
Affected Version(s)
IGEL OS 11 11.0.0
IGEL OS 12 12.0.0 <= 12.8.2
IGEL OS 12 12.0.0 <= 12.8.2
