CVE detail
CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 13.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
23 source links · newest first
- A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)watchTowr Labs
A long, long time ago, in a land free of binary exploit mitigations, when Unix still roamed the Earth, there lived a pre-authentication Telnetd vulnerability. In fact, this vulnerability was born so long ago (way back in 1994) that it may even be older than you. To put the
exploitlabs.watchtowr.comMar 19, 2026, 8:21 PM CVE-2026-32746 is a critical flaw in GNU InetUtils telnetd that allows remote attackers to execute code with elevated privileges Cybersecurity company Dream disclosed a critical flaw, tracked as CVE-2026-32746 (CVSS score of 9.8), in GNU InetUtils telnetd that lets unauthenticated remote attackers execute code with elevated privileges. The issue stems from an out-of-bounds write in […]
newssecurityaffairs.comMar 18, 2026, 3:06 PMIn 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code. Shockingly, the vulnerable code was almost 54 years old — and there was no patch available, and no expectation that one would be forthcoming. Fortunately, that’s because the […]
newswww.csoonline.comMar 5, 2026, 6:30 AM- Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point ElsewhereGreyNoise
nvestigate for signs of compromise. For GreyNoise customers: An IOC package and executive situation report (SITREP) for CVE-2026-1281 have been delivered to your inbox. Check your email for the full package, including indicators, detection guidance, and a board-ready summary. The Vulnerability and Timeline CVE-2026-1281 is a CVSS 9.8 (v3.1) unauthen
vendorwww.greynoise.ioFeb 10, 2026, 12:00 AM - U.S. CISA adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: […]
newssecurityaffairs.comJan 27, 2026, 2:54 PM The flaws allow threat actors to obtain root privileges or bypass authentication via Telnet and gain shell access as root.
newswww.securityweek.comJan 27, 2026, 10:37 AM- CVE-2026-24061Horizon3.ai
GNU InetUtils telnetd Authentication Bypass Vulnerability
exploithorizon3.aiJan 26, 2026, 3:48 PM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Osiris ransomware emerges, leveraging BYOVD technique to kill security tools U.S. CISA adds a flaw in […]
newssecurityaffairs.comJan 25, 2026, 12:29 AMCritical telnetd flaw CVE-2026-24061 (CVSS 9.8) affects all GNU InetUtils versions 1.9.3–2.7 and went unnoticed for nearly 11 years. A critical vulnerability, tracked as CVE-2026-24061 (CVSS score of 9.8), in the GNU InetUtils telnet daemon (telnetd) impacts all versions from 1.9.3 to 2.7. The vulnerability can be exploited to gain root access on affected systems. […]
newssecurityaffairs.comJan 24, 2026, 12:27 AMComputers with Telnet open are in immediate danger of being compromised due to a critical vulnerability that allows attackers to bypass authentication. The Telnet remote access protocol has long been superseded by the more secure and encrypted SSH, but many IoT and embedded devices have continued to ship with Telnet exposed on the LAN interface […]
newswww.csoonline.comJan 22, 2026, 10:28 PM- https://www.openwall.com/lists/oss-security/2026/01/20/2#:~:[email protected]%3A~%20USER='www.openwall.com
No excerpt available.
Exploitwww.openwall.comJan 21, 2026, 7:16 AM - https://www.labs.greynoise.io/grimoire/2026-01-22-f-around-and-find-out-18-hours-of-unsolicited-houseguests/index.htmlwww.labs.greynoise.io
No excerpt available.
Exploitwww.labs.greynoise.ioJan 21, 2026, 7:16 AM No excerpt available.
Mitigationwww.cisa.govJan 21, 2026, 7:16 AMNo excerpt available.
Vendor Advisorylists.debian.orgJan 21, 2026, 7:16 AM- http://www.openwall.com/lists/oss-security/2026/01/22/1www.openwall.com
No excerpt available.
Exploitwww.openwall.comJan 21, 2026, 7:16 AM - https://www.vicarius.io/vsociety/posts/cve-2026-24061-mitigation-script-remote-authentication-bypass-in-gnu-inetutils-packagewww.vicarius.io
No excerpt available.
Exploitwww.vicarius.ioJan 21, 2026, 7:16 AM - https://www.vicarius.io/vsociety/posts/cve-2026-24061-detection-script-remote-authentication-bypass-in-gnu-inetutils-packagewww.vicarius.io
No excerpt available.
Exploitwww.vicarius.ioJan 21, 2026, 7:16 AM - https://www.openwall.com/lists/oss-security/2026/01/20/8www.openwall.com
No excerpt available.
Exploitwww.openwall.comJan 21, 2026, 7:16 AM - https://www.openwall.com/lists/oss-security/2026/01/20/2www.openwall.com
No excerpt available.
Exploitwww.openwall.comJan 21, 2026, 7:16 AM - https://www.gnu.org/software/inetutils/www.gnu.org
No excerpt available.
Third Party Advisorywww.gnu.orgJan 21, 2026, 7:16 AM No excerpt available.
Exploitlists.gnu.orgJan 21, 2026, 7:16 AM- https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7bcodeberg.org
No excerpt available.
Patchcodeberg.orgJan 21, 2026, 7:16 AM - https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cccodeberg.org
No excerpt available.
Patchcodeberg.orgJan 21, 2026, 7:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.99 · max 6 stars
- jacubes/CVE-2026-24061High confidencegithubRepository topic discovery6 starsDiscovered Jul 14, 2026, 12:51 PM
- sh4den/CVE-2026-24061High confidencegithubDiscovery source unavailable5 starsDiscovered Jul 9, 2026, 1:19 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-52301CVSS 8.7 · High
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to chang…
- CVE-2022-45062CVSS 9.8 · Critical
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
- CVE-2022-3140CVSS 6.3 · Medium
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOff…
- CVE-2022-31084CVSS 8.1 · High
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 There are cases where LA…
- CVE-2022-25648CVSS 8.1 · High
The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter i…
- CVE-2022-23221CVSS 9.8 · Critical
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSC…