CVE-2026-82017
Received Received - Intake

Boot Parameter Injection in IGEL OS

Vulnerability report for CVE-2026-82017, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-31

Assigner: VulnCheck

Description

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-31
Generated
2026-09-18
AI Q&A
2026-08-29
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
igel igel_os to 12.7.6 (exc)
igel igel_os to 11.11.150 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a boot registry parameter injection flaw in IGEL OS versions before 12.7.6 (OS 12) and 11.11.150 (OS 11). Attackers with physical access can inject malicious Linux loader parameters into an unencrypted and unsigned configuration area. The signed bootloader reads this area, allowing arbitrary code execution with boot environment privileges without triggering TPM PCR measurement failures.

Detection Guidance

This vulnerability requires physical access to inject malicious boot parameters. Detection involves checking for unauthorized modifications to boot configuration files or unexpected kernel command line parameters. Inspect /boot/grub/grub.cfg or /boot/efi/EFI/IGEL/ for unencrypted changes. No direct network detection is possible as the attack occurs locally.

Impact Analysis

If you use IGEL OS versions before 12.7.6 or 11.11.150, an attacker with physical access to your device could exploit this to execute arbitrary code during boot. This could lead to unauthorized system access, data theft, or further compromise of the device and connected networks.

Compliance Impact

This vulnerability could violate compliance requirements that mandate secure boot processes, such as GDPR (data protection) or HIPAA (health data security). Unauthorized code execution during boot undermines integrity controls, potentially leading to data breaches or unauthorized access to sensitive information.

Mitigation Strategies

Upgrade IGEL OS to versions 12.7.6 or later for IGEL OS 12 and 11.11.150 or later for IGEL OS 11. Ensure physical access to devices is restricted. Verify bootloader integrity and disable unencrypted boot configurations if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82017. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart