GNU InetUtils disclosed a high-severity authentication bypass in telnetd, tracked as CVE-2026-24061, that allows a remote attacker to obtain a root shell by abusing how the daemon invokes /usr/bin/login. In affected versions 1.9.3 through 2.7, telnetd passes the client-controlled USER environment variable without proper sanitization, enabling an attacker to supply values such as -f root and trigger login’s authentication-bypass behavior. The flaw was reportedly introduced by a 2015 code change, remained present for more than a decade, and carries a CVSS 9.8 severity rating.
GNU InetUtils published patches to sanitize variable expansions used in the login invocation, including a broader hardening change after the initial fix, and advised administrators to upgrade or apply the available patches immediately. Where patching is not possible, maintainers and CSIRT.SK recommended disabling telnetd, restricting Telnet access to trusted IP addresses, considering a login(1) implementation that rejects the -f flag, and reviewing logs for signs of compromise. CSIRT.SK also reported that GreyNoise observed exploitation attempts in the wild, increasing the urgency for exposed systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that GreyNoise observed exploitation attempts targeting the telnetd vulnerability in the wild, indicating active attacker interest in the flaw.
The vulnerable code started shipping with GNU InetUtils version 1.9.3 in May 2015, beginning the affected range that continued through version 2.7.
On 2026-01-20, patches were developed and improved to sanitize variable expansions used when constructing the login invocation in telnetd.
GNU InetUtils states the vulnerability was reported on 2026-01-19. The issue allows a remote attacker to supply a crafted USER value such as "-f root" to bypass authentication and obtain root access.
The authentication-bypass flaw was introduced by a commit on March 19, 2015, when telnetd began passing client-controlled data into the login invocation without proper sanitization.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcecodeberg.org
Open sourceseclists.org
Open sourcecodeberg.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.