What happened
GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
Affected versions
InetUtils: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 52524GNU InetUtils 2.6 - Telnetd Remote Privilege Escalationaliguliyev2026-04-29VerifiedCVE-Intel · obrunolima1910/CVE-2026-24061🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.BypassPythonCRITICALAnalyzed★ 0⑂ 0EPSS 97.88%CVE data: CNACode indexedUpdated 26 Aug 2026Tags: agent, auth, book, computer-vision, cv, deep-learning, gluon, image-classificationobrunolima19102026-02-03CandidateCVE-Intel · jacubes/CVE-2026-24061CVE-2026-24061 exploit PoCPoCPythonCRITICALAnalyzed★ 824⑂ 15EPSS 97.88%CVE data: CNACode indexedUpdated 24 Aug 2026Tags: cve, cve-2026-24061, cve-poc, exploit, vulnerabilityjacubes2026-03-08CandidateCVE-Intel · SafeBreach-Labs/CVE-2026-24061Exploitation of CVE-2026-24061ExploitPythonCRITICALAnalyzed★ 207⑂ 47EPSS 97.88%CVE data: CNACode indexedUpdated 24 Aug 2026SafeBreach-Labs2026-01-22CandidateCVE-Intel · franckferman/CVE-2026-24061GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.InjectionPythonCRITICALAnalyzed★ 4⑂ 0EPSS 97.88%CVE data: CNACode indexedUpdated 21 Aug 2026Tags: authentication-bypass, cve, cve-2026-24061, cves, exploit, exploitation, exploiting, inetutilsfranckferman2026-02-02CandidateCVE-Intel · ekomsSavior/telnet_scanscanner/exploiter CVE-2026-24061 & CVE-2026-32746ExploitPythonCRITICALAnalyzed★ 12⑂ 6EPSS 97.88%CVE data: CNACode indexedUpdated 19 Aug 2026ekomsSavior2026-03-26CandidateCVE-Intel · 0p5cur/CVE-2026-24061-POCCVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the vulnerability from 2015 onwards.RCEPythonCRITICALAnalyzed★ 7⑂ 3EPSS 97.88%CVE data: CNACode indexedUpdated 11 Aug 2026Tags: cve, cve-2026-24061, poc, rce, root, telnet, telnet-server, unauthenticated-rce0p5cur2026-01-24CandidateCVE-Intel · s-vx/CVE-2026-24061Auth Bypass in inetutils-telnetdBypassPythonCRITICALAnalyzed★ 0⑂ 0EPSS 97.88%CVE data: CNACode indexedUpdated 25 Jul 2026s-vx2026-07-25CandidateCVE-Intel · Lingzesec/CVE-2026-24061-GUICVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具ExploitPythonCRITICALAnalyzed★ 17⑂ 1EPSS 97.88%CVE data: CNACode indexedUpdated 24 Jul 2026Lingzesec2026-01-26CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.