Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-82017
IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration Area
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
P L N N N H H H 8.6 .0021 10.7 —
AFFECTED
Product Versions Fixed
IGEL OS 12 12.0.0 – —
IGEL OS 11 11.0.0 – —
TIMELINE
Aug 27 Reserved by VulnCheck
Aug 28 Published (CNA: VulnCheck)
Aug 31 EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added.
Sep 24 EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added.
Oct 1 EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added.
Description
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.
Lifecycle
Complete event history — 5 events, chronological
| Date | Event | Detail |
| August 27, 2026 | Reserved | Reserved by VulnCheck |
| August 28, 2026 | Published | Published (CNA: VulnCheck) |
| August 31, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added. |
| September 24, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added. |
| October 1, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| IGEL | IGEL OS 12 | — | 12.0.0 | — |
| IGEL | IGEL OS 11 | — | 11.0.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-82017 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.