PT-2026-83366 · Igel · Igel Os

·

CVE-2026-82018

·

Published

2026-08-28

·

Updated

2026-08-29

CVSS v3.1

6.1

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IGEL OS 12 versions prior to 12.9.0 IGEL OS 12 version 12.8.3 LTS IGEL OS 11 versions prior to 11.11.150
Description A secure boot bypass exists in the GRUB boot stage. A physically present attacker can gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. This exploits a fail-open signature verification behavior in GRUB, allowing the attacker to access an interactive GRUB prompt and boot the device kernel with additional command-line arguments. This process results in a root shell with the disk unlocked while TPM PCR (Platform Configuration Registers) values remain unaltered.
Recommendations Update IGEL OS 12 to version 12.9.0 or later. Update IGEL OS 12 LTS to a version newer than 12.8.3. Update IGEL OS 11 to version 11.11.150 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82018

Affected Products

Igel Os