CVE-2026-82018
Received Received - Intake

Secure Boot Bypass in IGEL OS

Vulnerability report for CVE-2026-82018, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-02

Assigner: VulnCheck

Description

IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. Attackers can exploit GRUB's fail-open signature verification behavior to drop into an interactive GRUB prompt, then boot the device's own kernel with additional command-line arguments to obtain a root shell with the disk unlocked while leaving TPM PCR values unaltered.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-02
Generated
2026-09-18
AI Q&A
2026-08-29
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
igel igel_os to 12.9.0 (exc)
igel igel_os to 11.11.150 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-636 When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IGEL OS versions before 12.9.0, 12.8.3 LTS, and 11 before 11.11.150 have a secure boot bypass flaw in GRUB. Attackers with physical access can create an unsigned empty file named igel.conf on a partition to exploit GRUB's fail-open signature verification. This drops them into an interactive GRUB prompt, allowing them to boot the device's kernel with extra arguments to gain root access while leaving TPM PCR values unchanged.

Detection Guidance

Check for the presence of an unsigned empty file named igel.conf on any partition. Inspect GRUB configurations and boot partitions for unexpected files or modifications. Review system logs for unauthorized GRUB prompt access or boot arguments.

Impact Analysis

If you use affected IGEL OS versions, an attacker with physical access to your device could bypass secure boot protections. They could gain full root access to the system, potentially accessing sensitive data, installing malware, or modifying system configurations without detection.

Compliance Impact

This vulnerability could lead to unauthorized root access, compromising data confidentiality and integrity. For GDPR, it risks unauthorized access to personal data. For HIPAA, it may expose protected health information. Compliance could be violated due to insufficient protection against physical attacks.

Mitigation Strategies

Update IGEL OS to version 12.9.0 or later, 12.8.3 LTS, or 11.11.150 or later to patch the secure boot bypass. Ensure physical access controls are in place to prevent unauthorized booting. Monitor GRUB configurations for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82018. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart