logo

CVE-2026-24061: Decade-Old Vulnerability in GNU InetUtils telnetd Enables Remote Root Access

ID: 053db286-5176-5682-94fd-e8f76ec8828c

STIX ID: report--053db286-5176-5682-94fd-e8f76ec8828c

Feed Name: SOC Prime Blog

Threat Score
75/100

Date Published: 2026-01-23

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

A critical authentication bypass (CVE-2026-24061) in GNU InetUtils telnetd allows unauthenticated remote attackers to obtain root by supplying the USER environment variable value "-f root" combined with telnet's login options; the flaw affects InetUtils 1.9.3 through 2.7, was introduced in 2015, and researchers report active exploitation attempts observed in the wild. Immediate mitigation includes upgrading, restricting telnet access, disabling telnetd, or using a custom login that blocks the -f parameter.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.