Junglewise Threat Intelligence

CVE-2026-82017: IGEL OS boot registry parameter injection

CVE-2026-82017 · Severity: high · CVSS 7.6 · Published 2026-08-28

Executive brief

IGEL OS is a thin-client operating system used in enterprise environments to provide secure endpoint access. This vulnerability allows attackers with physical access to write malicious boot parameters to an unencrypted configuration area, enabling them to execute arbitrary commands with system-level privileges during startup and potentially compromise the entire device or access corporate networks.

Technical details

The vulnerability is a boot registry parameter injection flaw in IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150. An attacker with physical access can write unsigned, unencrypted kernel command line parameters to the boot registry (partition 4) that is read by the signed bootloader. By crafting malicious parameters (e.g., systemd.debug-shell=1), attackers can execute arbitrary Linux loader commands with boot environment privileges. The attack evades TPM PCR measurement checks because it does not modify the measured boot code itself, only the configuration area. Patches are available in IGEL OS 12.7.6 and IGEL OS 11.11.150 or later.

Affected products

  • IGEL OS 12 before 12.7.6, 11 before 11.11.150

Timeline

  • 2026-08-28: disclosed
  • 2026: patched: IGEL OS 12.7.6 and IGEL OS 11.11.150

References