CVE-2026-24061criticalunder attackCWE-88

CVE-2026-24061: critical vulnerability in GNU Inetutils

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 99%
from disclosure to weapon0 days
Published on NVDJan 21
1st PoCJul 3
metasploit+5d
CISA KEV+5d
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
128 public exploit(s)
Action required by CISAfederal deadline: 2026-02-16

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

A flaw in telnetd (a remote login service) allows attackers to bypass authentication and gain direct access as the root user by manipulating the USER environment variable. This is critical because it gives complete control of the system to unauthorized users.

Technical detail

telnetd in GNU Inetutils versions up to 2.7 fails to properly validate the USER environment variable, allowing remote attackers to bypass authentication by setting USER to "-f root". This enables unauthenticated remote code execution with root privileges. The vulnerability affects systems with telnetd enabled and exposed to untrusted networks.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
GNU · Inetutils
public PoCs found — 128
exploitdbwww.exploit-db.com/exploits/52524unverifiedgithubgithub.com/jacubes/CVE-2026-24061★ 825githubgithub.com/SafeBreach-Labs/CVE-2026-24061★ 208githubgithub.com/JayGLXR/CVE-2026-24061-POC★ 68githubgithub.com/ZeroDayEvil/CVE-2026-24061★ 22githubgithub.com/parameciumzhang/Tell-Me-Root★ 21githubgithub.com/Lingzesec/CVE-2026-24061-GUI★ 17githubgithub.com/ekomsSavior/telnet_scan★ 12githubgithub.com/leonjza/inetutils-telnetd-auth-bypass★ 12githubgithub.com/Chocapikk/CVE-2026-24061★ 12githubgithub.com/TryA9ain/CVE-2026-24061★ 10githubgithub.com/0p5cur/CVE-2026-24061-POC★ 8githubgithub.com/h3athen/CVE-2026-24061★ 8githubgithub.com/tc4dy/CVE-2026-24061-PoC-Exploit★ 7githubgithub.com/sh4den/CVE-2026-24061★ 6githubgithub.com/franckferman/CVE-2026-24061★ 5githubgithub.com/shivam-bathla/CVE-2026-24061-setup★ 4githubgithub.com/balgan/CVE-2026-24061★ 4githubgithub.com/madfxr/Twenty-Three-Scanner★ 4githubgithub.com/xuemian168/CVE-2026-24061★ 3githubgithub.com/K3ysTr0K3R/CVE-2026-24061★ 3githubgithub.com/X-croot/CVE-2026-24061_POC★ 2githubgithub.com/duy-31/CVE-2026-24061---telnetd★ 2githubgithub.com/0xBlackash/CVE-2026-24061★ 1githubgithub.com/infat0x/CVE-2026-24061★ 1githubgithub.com/MY0723/GNU-Inetutils-telnet-CVE-2026-24061-★ 1githubgithub.com/FurkanKAYAPINAR/CVE-2026-24061-telnet2root★ 1githubgithub.com/cumakurt/tscan★ 1githubgithub.com/setuju/telnetd★ 1githubgithub.com/JakeSwiz/telnet-inetutils-auth-bypass-CVE-2026-24061★ 1githubgithub.com/dotelpenguin/telnetd_CVE-2026-24061_tester★ 1githubgithub.com/monstertsl/CVE-2026-24061★ 1githubgithub.com/Mr-Zapi/CVE-2026-24061★ 1githubgithub.com/Cosm3No1de/htb-orion-writeup★ 0githubgithub.com/r00tuser111/CVE-2026-24061★ 0githubgithub.com/androidteacher/CVE-2026-24061-PoC-Telnetd★ 0githubgithub.com/tiborscholtz/CVE-2026-24061★ 0githubgithub.com/killsystema/scan-cve-2026-24061★ 0githubgithub.com/harygovind/CVE-2026-24061★ 0githubgithub.com/SeptembersEND/CVE--2026-24061★ 0githubgithub.com/skyejacobson/CyberhawksLab-telnetCVE★ 0githubgithub.com/z3n70/CVE-2026-24061★ 0githubgithub.com/ms0x08-dev/CVE-2026-24061-POC★ 0githubgithub.com/punitdarji/telnetd-cve-2026-24061★ 0githubgithub.com/XsanFlip/CVE-2026-24061-Scanner★ 0githubgithub.com/LucasPDiniz/CVE-2026-24061★ 0githubgithub.com/0x7556/CVE-2026-24061★ 0githubgithub.com/obrunolima1910/CVE-2026-24061★ 0githubgithub.com/iLokaas/CVE-2026-24061-payload★ 0githubgithub.com/athack-ctf/chall2026-telneted★ 0githubgithub.com/canpilayda/inetutils-telnetd-cve-2026-24061★ 0githubgithub.com/lavabyte/telnet-CVE-2026-24061★ 0githubgithub.com/Parad0x7e/CVE-2026-24061★ 0githubgithub.com/BrainBob/Telnet-TestVuln-CVE-2026-24061★ 0githubgithub.com/BrainBob/CVE-2026-24061★ 0githubgithub.com/Alter-N0X/CVE-2026-24061-POC★ 0githubgithub.com/typeconfused/CVE-2026-24061★ 0githubgithub.com/Mefhika120/Ashwesker-CVE-2026-24061★ 0githubgithub.com/midox008/CVE-2026-24061★ 0githubgithub.com/novitahk/Exploit-CVE-2026-24061★ 0githubgithub.com/Gabs-hub/CVE-2026-24061_Lab★ 0githubgithub.com/buzz075/CVE-2026-24061★ 0githubgithub.com/nrnw/CVE-2026-24061-GNU-inetutils-Telnet-Detector★ 0githubgithub.com/scumfrog/cve-2026-24061★ 0githubgithub.com/mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-★ 0githubgithub.com/kyukazamiqq/CVE-2026-24061★ 0githubgithub.com/przemytn/CVE-2026-24061★ 0githubgithub.com/ahmadsadeeq/TelnetdBypass-★ 0githubgithub.com/anxs3c/CVE-2026-24061-GNU-InetUtils-telnetd★ 0githubgithub.com/akpmarcelin/CVE-2026-24061-lab★ 0githubgithub.com/stoerti2/Abyssal★ 0githubgithub.com/s-vx/CVE-2026-24061★ 0githubgithub.com/Ish3ng0m4/CVE-2026-24061-Telnetd★ 0githubgithub.com/HD0x01/CVE-2026-24061-NSE★ 0vulncheckvulncheck.com/xdb/027ac3b5fcd3unverifiedvulncheckvulncheck.com/xdb/01bf6bfce293unverifiedvulncheckvulncheck.com/xdb/e14b60108668unverifiedvulncheckvulncheck.com/xdb/037f09ac8bd2unverifiedvulncheckvulncheck.com/xdb/281c93516f03unverifiedvulncheckvulncheck.com/xdb/4fe4957aaafeunverifiedvulncheckvulncheck.com/xdb/e8b0b325123funverifiedvulncheckvulncheck.com/xdb/cdc425361e5aunverifiedvulncheckvulncheck.com/xdb/ce38d836a6d4unverifiedvulncheckvulncheck.com/xdb/6c64eec2246funverifiedvulncheckvulncheck.com/xdb/2095407cd24eunverifiedvulncheckvulncheck.com/xdb/1965f3150b25unverifiedvulncheckvulncheck.com/xdb/9d90ab411f9cunverifiedvulncheckvulncheck.com/xdb/089b79c9b65cunverifiedvulncheckvulncheck.com/xdb/14ec796d456eunverifiedvulncheckvulncheck.com/xdb/45d6d2515c7eunverifiedvulncheckvulncheck.com/xdb/ac3246834fa8unverifiedvulncheckvulncheck.com/xdb/05724362c1bdunverifiedvulncheckvulncheck.com/xdb/07cf2b439a9dunverifiedvulncheckvulncheck.com/xdb/a4bd074b1edcunverifiedvulncheckvulncheck.com/xdb/df7878b9e432unverifiedvulncheckvulncheck.com/xdb/cbd3b8d0a002unverifiedvulncheckvulncheck.com/xdb/8036e0e4aba4unverifiedvulncheckvulncheck.com/xdb/e8d1ce668bd6unverifiedvulncheckvulncheck.com/xdb/36c2b1e5c7dcunverifiedvulncheckvulncheck.com/xdb/107b81fce065unverifiedvulncheckvulncheck.com/xdb/e03fbca3008cunverifiedvulncheckvulncheck.com/xdb/fe99751b4742unverifiedvulncheckvulncheck.com/xdb/4fa764154266unverifiedvulncheckvulncheck.com/xdb/960fcc9bd89cunverifiedvulncheckvulncheck.com/xdb/e97f97610013unverifiedvulncheckvulncheck.com/xdb/febad18902a8unverifiedvulncheckvulncheck.com/xdb/5026f54ecaaeunverifiedvulncheckvulncheck.com/xdb/f1b5a45051d3unverifiedvulncheckvulncheck.com/xdb/a4152661a60cunverifiedvulncheckvulncheck.com/xdb/156d503457bcunverifiedvulncheckvulncheck.com/xdb/9f3ce3e6ca21unverifiedvulncheckvulncheck.com/xdb/0736e00f5aceunverifiedvulncheckvulncheck.com/xdb/f05b1fb3f5a1unverifiedvulncheckvulncheck.com/xdb/0bab298804b5unverifiedvulncheckvulncheck.com/xdb/e90c23bb7208unverifiedvulncheckvulncheck.com/xdb/a7890dd1271eunverifiedvulncheckvulncheck.com/xdb/193b14870c6cunverifiedvulncheckvulncheck.com/xdb/4a52280d4be4unverifiedvulncheckvulncheck.com/xdb/eb6ce1666294unverifiedvulncheckvulncheck.com/xdb/0ecc49d5a1f0unverifiedvulncheckvulncheck.com/xdb/57ee6813a50eunverifiedvulncheckvulncheck.com/xdb/bd5639365990unverifiedcve_referencewww.openwall.com/lists/oss-security/2026/01/20/2#:~:text=root@...a%3A~%20USER='unverifiedvulncheckvulncheck.com/xdb/53db998fa024unverifiedvulncheckvulncheck.com/xdb/59d8a7fe1a59unverifiedvulncheckvulncheck.com/xdb/04059d8aed83unverifiedvulncheckvulncheck.com/xdb/137fff97fa8dunverifiedvulncheckvulncheck.com/xdb/ec801fb614c1unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.