GNU InetUtils disclosed CVE-2026-24061, a high-severity authentication bypass in telnetd that can let a remote client obtain root access without valid credentials. The bug affects versions 1.9.3 through 2.7 and stems from telnetd passing a client-controlled USER environment variable to /usr/bin/login without sanitization; a crafted value such as -f root can cause login(1) to skip normal authentication. The vulnerable code path was traced to a 2015 commit later shipped in the 1.9.3 release, and maintainers published patches while advising organizations not to run telnetd, to restrict access to trusted clients, and to upgrade to a fixed release.
Public attention quickly expanded beyond the advisory as security researchers and developers published multiple proof-of-concept exploits, scanners, Nuclei templates, test harnesses, and detection content on GitHub and in vendor repositories. Those references describe tooling for discovery and exploitation of the NEW_ENVIRON/USER injection path, including lab environments and root-shell demonstrations, increasing the likelihood of opportunistic targeting against exposed Telnet services. The combination of a remotely reachable root bypass and rapidly available offensive tooling makes internet-facing or internally exposed GNU InetUtils telnetd instances an urgent remediation priority.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Splunk added a security content story covering telnetd CVE-2026-24061, indicating vendor-side detection and monitoring guidance had become available. This reflected defender response to the now-public vulnerability and exploit activity.
A more advanced public framework for discovering and exploiting CVE-2026-24061 was published on GitHub, advertising asynchronous scanning, fingerprinting, and exploitation capabilities. This represented an escalation from simple PoCs to broader operational tooling.
Further GitHub repositories published exploit code and lab environments for CVE-2026-24061, lowering the barrier to reproducing and testing the issue. Public exploit development expanded rapidly after the initial disclosure.
Security tooling and detection artifacts for the vulnerability began appearing publicly, including a Nuclei template and tester repositories. These resources enabled defenders and researchers to identify exposed vulnerable telnetd services.
A GitHub repository publishing a proof of concept for CVE-2026-24061 was made public, demonstrating exploitability of the telnetd authentication bypass. This marked the start of broad public exploit tooling availability.
Media coverage drew broader attention to the telnetd flaw, emphasizing that affected GNU InetUtils telnetd deployments could hand attackers root access without authentication. This reporting amplified awareness beyond the original advisory.
GNU InetUtils publicly disclosed a high-severity telnetd vulnerability that can let a remote client log in as root without normal authentication by passing a crafted USER value such as "-f root" to /usr/bin/login. The issue was reported by Kyu Neushwaistein aka Carlos Cortes Alvarez, and patches were prepared by Paul Eggert and improved by Simon Josefsson.
The vulnerable code was included in GNU InetUtils 1.9.3, making versions 1.9.3 through 2.7 affected by the authentication bypass. The advisory identifies 1.9.3, released on 2015-05-12, as the first impacted release.
A commit introduced the telnetd flaw that later became CVE-2026-24061, allowing client-controlled USER environment data to influence login behavior. The advisory states this vulnerable code was added on 2015-03-19.
18 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcetheregister.com
Open sourceseclists.org
Open sourcelists.gnu.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.