SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82017

HIGH · CVSS 7.6 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

IGEL OS versions prior to 12.7.6 and 11.11.150 are vulnerable to a boot registry parameter injection flaw that enables attackers with physical access to execute arbitrary Linux loader parameters. This vulnerability allows for the injection of malicious kernel command line parameters, granting elevated privileges during the boot process without triggering security mechanisms. Organizations using affected IGEL OS versions should prioritize remediation to mitigate potential unauthorized access and system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82017
Severity
HIGH
CVSS
7.6
EPSS
0.15%
Linux

Original NVD Description

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.