Untriaged
Permalink
CVE-2026-24061
9.8 CRITICAL
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass …
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
References
-
https://www.labs.greynoise.io/grimoire/2026-01-22-f-around-and-find-out-18-hour… third-party-advisory
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026… government-resource
Affected products
Inetutils
- =<2.7
Package maintainers
-
@matthewbauer Matthew Bauer <mjbauer95@gmail.com>