ISN 2026-19: Code Execution via Boot Registry

First published 16 June 2026

CVSS:3.1: 7.6 (High)

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Summary

A security vulnerability has been found in the IGEL OS Boot Registry. This affects the following product versions:

  • IGEL OS 12

  • IGEL OS 11

Details

The IGEL OS Boot Registry can be manipulated by an attacker with physical access in order to execute arbitrary code. This has been discovered in a penetration test commissioned by IGEL.

Update Instructions

  • OS 12: Upgrade the Base system app to version 12.7.6 or newer.

  • OS 11: Upgrade to IGEL OS 11.11.150.