Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. Attackers can exploit GRUB's fail-open signature verification behavior to drop into an interactive GRUB prompt, then boot the device's own kernel with additional command-line arguments to obtain a root shell with the disk unlocked while leaving TPM PCR values unaltered. | |
| Title | IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File | |
| Weaknesses | CWE-636 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T21:11:43.223Z
Reserved: 2026-08-27T21:39:20.459Z
Link: CVE-2026-82018
No data.
Status : Received
Published: 2026-08-28T22:16:55.217
Modified: 2026-08-28T22:16:55.217
Link: CVE-2026-82018
No data.
OpenCVE Enrichment
No data.