CVE-2026-24061
Confirmed PUBLISHEDtelnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
1 day faster than CISA KEV
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
- CVE Published
- Jan 21, 2026
- Exploitation Reported
- Jun 01, 2026
- CVSS
- 9.8 Critical
- EPSS
- 98.9%
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| GNU |
Inetutils
|
1.9.3 to <= 2.7 |
Affected |
CVE References
- OSS-Security Mailing List openwall.com · CVE Record https://www.openwall.com/lists/oss-security/2026/01/20/2
- OSS-Security Mailing List openwall.com · CVE Record https://www.openwall.com/lists/oss-security/2026/01/20/8
- gnu.org/software/inetutils gnu.org · CVE Record https://www.gnu.org/software/inetutils/
- lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.... lists.gnu.org · CVE Record https://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.html
- codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398... codeberg.org · CVE Record https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739...
Show 3 more references
- codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a3... codeberg.org · CVE Record https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d77...
- vicarius.io/vsociety/posts/cve-2026-24061-detection-scri... vicarius.io · CVE Record https://www.vicarius.io/vsociety/posts/cve-2026-24061-detection-scrip...
- vicarius.io/vsociety/posts/cve-2026-24061-mitigation-scr... vicarius.io · CVE Record https://www.vicarius.io/vsociety/posts/cve-2026-24061-mitigation-scri...
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CVE First | 2026-06-01 10:49 UTC |
| CISA | 2026-06-02 14:03 UTC |
No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
Exploited in the wild
Recorded 2026-06-01 10:49:50 UTC · CVE
Proof of concept available
Recorded 2026-03-18 19:58:51 UTC · GitHub
Weaknesses (CWE)
-
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-06-27 23:44:42 UTC · 0 stars
github · Created 2026-06-17 19:59:24 UTC · 0 stars
github · Created 2026-06-08 17:36:36 UTC · 0 stars
GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
github · Created 2026-06-08 17:36:36 UTC · 0 stars
GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
github · Created 2026-06-08 15:04:56 UTC · 1 stars
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
github · Created 2026-06-06 12:38:43 UTC · 0 stars
🚀 CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass Exploit - Full Control 💥 CRLF injection via NEW_ENVIRON leads to auth bypass & instant root shell. ✅ Single/Mass exploitation, multi-threading, custom port/user, pipe mode, session keep-alive, colored output, retries, timeout support. ⚡ Python & Bash versions. Critical CVSS 9.8.
github · Created 2026-03-18 19:58:51 UTC · 0 stars
CVE-2026-24061 PoC - telnetd auth bypass
github · Created 2026-03-16 14:55:50 UTC · 0 stars
The script performs a full Telnet negotiation mirroring the exact byte sequence of a real telnet -a client session.
github · Created 2026-03-08 11:25:39 UTC · 202 stars
CVE-2026-24061 exploit PoC
github · Created 2026-02-18 08:52:25 UTC · 0 stars
github · Created 2026-02-14 10:22:37 UTC · 0 stars
A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, which contains automatic username injection using the NEW-ENVIRON option.
github · Created 2026-02-06 00:36:20 UTC · 0 stars
A passive detection tool for identifying potential exposure to CVE-2026-24061 in GNU inetutils telnet installations
github · Created 2026-02-04 19:22:29 UTC · 0 stars
github · Created 2026-02-03 19:46:10 UTC · 0 stars
🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.
github · Created 2026-02-02 23:20:01 UTC · 4 stars
CVE-2026-24061 PoC and walkthrough
github · Created 2026-02-01 20:32:26 UTC · 1 stars
POC Script for CVE-2026-24061 (GNU Telnetd Exploit)
github · Created 2026-01-31 01:10:23 UTC · 0 stars
Scanner for CVE-2026-24061
github · Created 2026-01-31 00:41:11 UTC · 1 stars
This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is going on right now. Why people are still using Telnet... beyond me.
github · Created 2026-01-28 22:03:09 UTC · 1 stars
Checks for CVE-2026-24061 Telnetd exploit
github · Created 2026-01-28 15:41:27 UTC · 0 stars
github · Created 2026-01-28 14:35:20 UTC · 0 stars
CVE-2026-24061 Telnet RCE Exploit For Linux MacOS Windows
github · Created 2026-01-28 02:54:23 UTC · 1 stars
GNU Inetutils telnet远程认证绕过漏洞(CVE-2026-24061),该漏洞源于 GNU Inetutils telnetd 组件中对环境变量处理不当,攻击者可利用该漏洞,通过构造恶意的 USER 环境变量并发送至受影响的 telnet 服务,触发认证绕过机制,进而实现无需密码直接获取root权限。
github · Created 2026-01-28 00:27:09 UTC · 0 stars
Lab to show the CVE-2026-24061
github · Created 2026-01-27 20:04:40 UTC · 0 stars
Payload CVE-2026-24061
github · Created 2026-01-27 14:24:19 UTC · 0 stars
github · Created 2026-01-27 08:32:42 UTC · 1 stars
github · Created 2026-01-26 20:46:49 UTC · 0 stars
Vulnerability in GNU InetUtils telnetd Enables Remote Root Access
github · Created 2026-01-26 09:58:04 UTC · 16 stars
CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具
github · Created 2026-01-26 07:47:36 UTC · 0 stars
CVE-2026-24061-Scanner by XsanLahci
github · Created 2026-01-25 19:22:38 UTC · 0 stars
github · Created 2026-01-25 08:51:17 UTC · 0 stars
CVE-2026-24061
github · Created 2026-01-25 07:33:48 UTC · 0 stars
GNU telnetd service from GNU InetUtils authentication-bypass
github · Created 2026-01-24 23:21:56 UTC · 0 stars
CVE-2026-24061 - GNU InetUtils telnetd authentication bypass POC + Docker lab environment for testing
github · Created 2026-01-24 19:03:06 UTC · 4 stars
Docker setup for CVE-2026-24061
github · Created 2026-01-24 17:54:40 UTC · 7 stars
CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the vulnerability from 2015 onwards.
github · Created 2026-01-24 15:11:28 UTC · 0 stars
github · Created 2026-01-24 13:18:54 UTC · 0 stars
Nuclei template for CVE-2026-24061
github · Created 2026-01-24 08:09:02 UTC · 0 stars
github · Created 2026-01-23 17:26:43 UTC · 5 stars
Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers to gain instant root shell access via malicious NEW_ENVIRON telnet option exploitation.
github · Created 2026-01-23 17:26:43 UTC · 5 stars
Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers to gain instant root shell access via malicious NEW_ENVIRON telnet option exploitation.
github · Created 2026-01-23 12:33:03 UTC · 2 stars
inetutils-telnetd Authentication Bypass - working
github · Created 2026-01-23 02:14:15 UTC · 3 stars
github · Created 2026-01-22 18:30:17 UTC · 206 stars
Exploitation of CVE-2026-24061
github · Created 2026-01-22 14:27:50 UTC · 65 stars
github · Created 2026-01-22 14:24:19 UTC · 11 stars
github · Created 2026-01-22 10:48:22 UTC · 8 stars
CVE-2026-24061 Batch Scanning Tool
github · Created 2026-01-22 10:38:31 UTC · 2 stars
Bypass d’authentification Telnet menant à un accès root
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
14:03 UTC about 2 months ago14:03 UTC · about 2 months ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
10:49 UTC about 2 months ago10:49 UTC · about 2 months ago
Added to KEVIntel KEV Feed
High-confidence, third-party attested exploitation
-
10:38 UTC 6 months ago10:38 UTC · 6 months ago
Public PoC available
Public proof-of-concept code published
-
06:42 UTC 6 months ago06:42 UTC · 6 months ago
CVE published
Vulnerability disclosed publicly
-
06:42 UTC 6 months ago06:42 UTC · 6 months ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2026-24061
{
"cve_id": "CVE-2026-24061",
"title": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via ...",
"affected_vendor": "GNU",
"affected_product": "Inetutils",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 9.8,
"epss_score": 0.98871,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}