๐Ÿ” CVE Alert

CVE-2026-82018

MEDIUM 6.1

IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. Attackers can exploit GRUB's fail-open signature verification behavior to drop into an interactive GRUB prompt, then boot the device's own kernel with additional command-line arguments to obtain a root shell with the disk unlocked while leaving TPM PCR values unaltered.

CWE CWE-636
Vendor igel
Product igel os 12
Published Aug 28, 2026
Last Updated Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for igel igel os 12

Be the first to know when new medium vulnerabilities affecting igel igel os 12 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

IGEL / IGEL OS 12
12.0.0 โ‰ค 12.8.2
IGEL / IGEL OS 11
11.0.0 < 11.11.150

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
kb.igel.com: https://kb.igel.com/en/security-safety/current/isn-2026-20-grub-shell-escape-in-igel-os blog.amberwolf.com: https://blog.amberwolf.com/blog/2026/august/thin-client-thin-crypto-overview/ media.defcon.org: https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20Darren%20McDonald%20-%20Thin%20Client%20Thin%20Crypto%20-%20Bypassing%20Full-Desk%20Encryption%20Across%20Three%20Major%20Thin%20Clients%20Vendors%20without%20Breaking%20a%20Ci.pdf vulncheck.com: https://www.vulncheck.com/advisories/igel-os-12-11-secure-boot-bypass-via-unsigned-igel-conf-file

Credits

Darren McDonald from AmberWolf