HIGHCVSS 7.6Vulnerability

CVE-2026-82017

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.

Properties

severity
HIGH
cvss_severity
HIGH
cvss_score
7.6
retrieved_at
2026-09-25T15:10:03+00:00
score
7.6
last_source
NVD
cve_id
CVE-2026-82017
cvss_vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-09-25T15:10:03+00:00
vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-28T22:16:55.067
last_modified
2026-09-24T20:44:42.207

Related Entities (2)

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Insufficient Verification of Data Authenticity

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82017 (CVSS 7.6) — Ninja Signal Threat Intelligence | Ninja Signal