A critical authentication-bypass vulnerability was disclosed in GNU InetUtils telnetd that allows a remote, unauthenticated attacker to obtain access as root (or any known user) by supplying a crafted USER environment variable. The issue arises because telnetd passes the remote-supplied USER value to /usr/bin/login without sanitization; an attacker can set USER to -f root, leveraging the login(1) -f option to bypass normal authentication checks and immediately gain privileged access. Reported by Simon Josefsson, the flaw appears to have been introduced in 2015 and affects GNU InetUtils versions 1.9.3 and later (with reporting indicating impact through at least 2.7); at the time of reporting, no CVE had been assigned.
Mitigations emphasized include disabling Telnet (preferred due to the protocol’s inherent insecurity), restricting access to trusted clients via network controls, and applying upstream fixes where available. Operationally, defenders are advised to rapidly identify exposed services—particularly Linux systems running Telnet—because exploitation requires only network reachability to telnetd and results in full system compromise; one approach suggested for discovery is querying asset inventories for Linux hosts offering Telnet (e.g., os:Linux protocol:telnet) and then validating which implementation is in use before prioritizing remediation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
SafeBreach Labs released a technical analysis and public Python proof-of-concept showing how the %U placeholder and Telnet environment handling enable argument injection into login. The research also noted attackers could influence additional environment variables such as PATH and recommended upgrading to the patched release.
Security reporting on 2026-01-23 described a coordinated campaign exploiting CVE-2026-24061, with observed reconnaissance, SSH key persistence attempts, and failed Python malware deployment after initial access. The activity appeared largely automated and focused on quickly turning unauthenticated access into root-level persistence.
By 2026-01-22, multiple national cybersecurity authorities and security vendors were warning that exploitation was straightforward and recommending decommissioning telnet, migrating to SSH, patching, or tightly restricting access. Public reporting also highlighted active scanning and exploitation attempts from multiple IPs shortly after disclosure.
GreyNoise observed malicious exploitation activity starting on 2026-01-21, with attackers using Telnet option negotiation to inject USER values and obtain shell access. Reporting described 18 attacker IPs across 60 sessions, with root targeted in most cases.
GNU InetUtils 2.8 was released to patch the telnetd authentication bypass vulnerability. Guidance accompanying coverage recommended upgrading immediately or disabling telnetd and restricting TCP/23 access where patching was not possible.
The critical telnetd flaw was publicly disclosed as CVE-2026-24061, with a CVSS score of 9.8, describing how a crafted USER value such as "-f root" can bypass authentication and yield root access. Public reporting on 2026-01-20 also noted affected versions beginning at 1.9.3.
Security researcher Kyu Neushwaistein (Carlos Cortes Alvarez) reported the GNU InetUtils telnetd authentication bypass issue. Multiple sources place the report on 2026-01-19.
GNU InetUtils version 1.9.3 was released with the vulnerable telnetd behavior, making affected versions start at 1.9.3. The bug then persisted across subsequent releases up to 2.7.
A source code change on 2015-03-19 introduced the telnetd argument-injection flaw by allowing client-controlled USER data to be passed into the login invocation. This created the basis for later authentication bypass and root access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
safebreach.com
Open sourcedarkreading.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcerunzero.com
Open sourcerunzero.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.