GNU telnetd auth bypass CVE-2026-24061
ID: 764357ee-62b5-55b0-8ee8-3f0ebaa36306
STIX ID: report--764357ee-62b5-55b0-8ee8-3f0ebaa36306
Feed Name: Kudelski Security
**Executive Summary:** CVE-2026-24061 is a critical remote code execution flaw in GNU Inetutils telnetd (v1.9.3 through v2.7) that permits an attacker to inject a crafted USER environment variable during telnet negotiation, causing /usr/bin/login to be invoked with -f and granting an unauthenticated root shell; SafeBreach Labs published a PoC and CISA added the issue to its Known Exploited Vulnerabilities list, and recommended mitigations include upgrading to patched telnetd, disabling telnet, or restricting access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
