Back

MEDIUM

IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File

Published Aug 28, 2026

Description

IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. Attackers can exploit GRUB's fail-open signature verification behavior to drop into an interactive GRUB prompt, then boot the device's own kernel with additional command-line arguments to obtain a root shell with the disk unlocked while leaving TPM PCR values unaltered.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 28, 2026
Updated Oct 1, 2026
Reserved Aug 27, 2026
CISA Vulnrichment
Updated Sep 2, 2026
NVD
Status Received
Modified Sep 2, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Aug 28, 2026
Updated Oct 1, 2026
Exploited since n/a
EUVD-2026-67962