CRITICAL
CVE-2026-24061
CVSS
9.8
KEV
Description
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Summary dbcve.org
The telnetd server in GNU Inetutils through version 2.7 contains an authentication bypass vulnerability where an attacker can set the USER environment variable to '-f root' to bypass authentication and gain root access without valid credentials.
Mitigation
Upgrade to GNU Inetutils version beyond 2.7 when a patch is available, or disable telnetd entirely and migrate to SSH which does not have this vulnerability.
Weakness (CWE)
CWE-88
EPSS Score
98.06%
Probability of exploitation in next 30 days
99.9th percentile
References
https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc
Patch
https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7b
Patch
https://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.html
Mitigation, Vendor Advisory
https://www.gnu.org/software/inetutils/
Product
https://www.openwall.com/lists/oss-security/2026/01/20/2
Mailing List
https://www.openwall.com/lists/oss-security/2026/01/20/8
Mailing List
https://www.vicarius.io/vsociety/posts/cve-2026-24061-detection-script-remote-authentication-bypass-in-gnu-inetutils-package
Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2026-24061-mitigation-script-remote-authentication-bypass-in-gnu-inetutils-package
Mitigation, Third Party Advisory
http://www.openwall.com/lists/oss-security/2026/01/22/1
Mailing List
https://lists.debian.org/debian-lts-announce/2026/01/msg00025.html
Mailing List, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24061
US Government Resource
https://www.labs.greynoise.io/grimoire/2026-01-22-f-around-and-find-out-18-hours-of-unsolicited-houseguests/index.html
Exploit, Third Party Advisory
https://www.openwall.com/lists/oss-security/2026/01/20/2#:~:text=root@...a%3A~%20USER='
Mailing List, Third Party Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.