CVE-2026-24061
GNU InetUtils Argument Injection Vulnerability
- Published
- Jan 21, 2026
- Updated
- Mar 25, 2026
- Assigning CNA
- mitre
- Evidence observed
- Jan 26, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Sources
73CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the vulnerability from 2015 onwards.
- CVE-2026-24061Exploit
Cross-platform remote code execution exploit for GNU Inetutils telnet (versions 1.9.3 to 2.7), targeting CVE-2026-24061 with a simple command-line interface.
- CVE-2026-24061Exploit
CVE-2026-24061
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.