Description
IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. Attackers can exploit GRUB's fail-open signature verification behavior to drop into an interactive GRUB prompt, then boot the device's own kernel with additional command-line arguments to obtain a root shell with the disk unlocked while leaving TPM PCR values unaltered.
Published: 2026-08-28
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a physically present attacker to place an unsigned, empty igel.conf file on a device that runs IGEL OS 11 or 12. During the GRUB boot stage, the bootloader accepts the file and drops the user into an interactive GRUB prompt. From there the attacker can load the device’s own kernel with arbitrary command‑line arguments, which grants a root shell while keeping the TPM PCR values unchanged. This escalation gives the attacker full control over the machine and bypasses the device’s full‑desk encryption, enabling read, write, or modify operations on data that would normally be protected by secure boot and disk encryption.

Affected Systems

The vulnerability affects IGEL OS 12 versions prior to 12.9.0 (including 12.8.3 LTS) and IGEL OS 11 versions older than 11.11.150. It is limited to the GRUB boot process on IGEL thin‑client hardware running those OS builds and requires local physical access to the system to place the igel.conf file.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity. While the exploit requires physical presence and local access, it is straightforward to carry out with knowledge of the device’s file system. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, meaning no large‑scale automated exploitation has been observed. Nevertheless, an attacker with physical access can gain complete root privileges and compromise confidentiality, integrity, and availability of system resources.

Generated by OpenCVE AI on August 28, 2026 at 23:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade IGEL OS 12 to version 12.9.0 or later, or upgrade IGEL OS 11 to 11.11.150 or later, as released by the vendor.
  • Remove any unsigned igel.conf file from the system partition and verify that all configuration files are signed by the vendor.
  • Configure GRUB to enforce signature verification and disallow fall‑back to the interactive prompt if a configuration option exists, ensuring that only signed configuration files are accepted.

Generated by OpenCVE AI on August 28, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. Attackers can exploit GRUB's fail-open signature verification behavior to drop into an interactive GRUB prompt, then boot the device's own kernel with additional command-line arguments to obtain a root shell with the disk unlocked while leaving TPM PCR values unaltered.
Title IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File
Weaknesses CWE-636
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-28T21:11:43.223Z

Reserved: 2026-08-27T21:39:20.459Z

Link: CVE-2026-82018

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:55.217

Modified: 2026-08-28T22:16:55.217

Link: CVE-2026-82018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:00:15Z

Weaknesses
  • CWE-636

    Not Failing Securely ('Failing Open')