CVE-2026-24061: critical vulnerability in GNU Inetutils
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
A flaw in telnetd (a remote login service) allows attackers to bypass authentication and gain direct access as the root user by manipulating the USER environment variable. This is critical because it gives complete control of the system to unauthorized users.
telnetd in GNU Inetutils versions up to 2.7 fails to properly validate the USER environment variable, allowing remote attackers to bypass authentication by setting USER to "-f root". This enables unauthenticated remote code execution with root privileges. The vulnerability affects systems with telnetd enabled and exposed to untrusted networks.
The full analysis of this CVE is available in Portuguese →