{"id":"CVE-2026-24061","title":"telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.","summary":"telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-88"],"vendor":"gnu","product":"inetutils","affected":["inetutils >= 1.9.3, <= 2.7","debian_linux = 11.0"],"published":"2026-01-21","updated":"2026-09-29","sourceUpdated":"2026-09-29T20:17:19.750","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-24061","references":[{"url":"https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc","label":"cve@mitre.org"},{"url":"https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7b","label":"cve@mitre.org"},{"url":"https://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.html","label":"cve@mitre.org"},{"url":"https://redteam.ae/blog/cve-2026-24061-inetutils-telnetd-root-bypass","label":"cve@mitre.org"},{"url":"https://www.gnu.org/software/inetutils/","label":"cve@mitre.org"},{"url":"https://www.openwall.com/lists/oss-security/2026/01/20/2","label":"cve@mitre.org"},{"url":"https://www.openwall.com/lists/oss-security/2026/01/20/8","label":"cve@mitre.org"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-24061-detection-script-remote-authentication-bypass-in-gnu-inetutils-package","label":"cve@mitre.org"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-24061-mitigation-script-remote-authentication-bypass-in-gnu-inetutils-package","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/01/22/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00025.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24061","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.labs.greynoise.io/grimoire/2026-01-22-f-around-and-find-out-18-hours-of-unsolicited-houseguests/index.html","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.openwall.com/lists/oss-security/2026/01/20/2#:~:text=root@...a%3A~%20USER='","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","in-the-wild","exploit-available","kev"],"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-01-27T04:55:30.344896Z"},"epss":0.98984,"epssPercentile":0.99929,"kev":true,"kevDateAdded":"2026-01-26","kevDueDate":"2026-02-16","kevRansomware":false,"exploits":{"exploitdb":true,"github":72,"githubRepos":["https://github.com/jacubes/CVE-2026-24061","https://github.com/SafeBreach-Labs/CVE-2026-24061","https://github.com/JayGLXR/CVE-2026-24061-POC"],"metasploit":["exploit/linux/telnet/gnu_inetutils_auth_bypass"],"checkedAt":"2026-09-29T20:46:41.292Z"},"ingestedAt":"2026-09-29T20:46:06.407Z","slug":"CVE-2026-24061","body":"## Overview\n\ntelnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.\n\n## Affected\n\n- `inetutils >= 1.9.3, <= 2.7`\n- `debian_linux = 11.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":99,"depthScoreParts":{"impact":53.9,"likelihood":19.8,"exploitation":25,"ransomware":0},"changes":[]}