CVE-2026-28372 is a privilege-escalation vulnerability in GNU inetutils telnetd through version 2.7. The flaw arises because telnetd accepts client-supplied environment variables via the Telnet NEW-ENVIRON option and invokes login(1) with environment preservation enabled, allowing the CREDENTIALS_DIRECTORY variable to reach the system login process. On systems using util-linux login(1) version 2.40 or later, login supports systemd service credentials and checks for a login.noauth marker in the directory referenced by CREDENTIALS_DIRECTORY. If that marker indicates authentication should be skipped, login grants a shell for the requested account without verifying credentials. An attacker can abuse this behavior by causing telnetd to pass a controlled CREDENTIALS_DIRECTORY value and selecting a target account such as root. The issue is fundamentally an unsafe external control of process environment affecting a security decision in a downstream privileged program.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small collection of three standalone Python proof-of-concept exploits plus a README and license. It is not tied to a common exploitation framework. The code files are CVE-2026-28372.py, CVE-2026-4408.py, and CVE-2026-4480.py, each with its own argparse-based CLI and main() entry point. CVE-2026-28372.py is a Telnet client-side exploit for a TelnetD authentication bypass/local privilege escalation scenario. It implements Telnet option negotiation manually, specifically NEW-ENVIRON handling, and injects environment variables into the server-side login process. Before connecting, it creates a local file at /tmp/login.noauth by default containing 'yes'. It then sets CREDENTIALS_DIRECTORY to the parent directory of that file and USER to the requested username (default root). The exploit connects to the target Telnet service, responds to DO/WILL/SB negotiation, sends the crafted environment block, and provides an interactive session. Main capability: bypass login authentication and obtain a shell as root or another chosen user. Attack vector is network to the Telnet service, but the vulnerability effect is local privilege escalation on the target. CVE-2026-4408.py is a Samba SAMR remote code execution PoC built with Impacket DCERPC primitives. It binds to Samba over ncacn_ip_tcp and either uses a user-specified port or brute-forces the likely dynamic SAMR port range 49152-49251. The exploit crafts a SAM_VALIDATE_INPUT_ARG structure and abuses hSamrValidatePassword by placing the attacker-controlled command string into UserAccountName. The README explains this reaches a vulnerable 'check password script' path where %u is inserted into a shell command without proper escaping. Main capability: remote arbitrary command execution on a Samba host, optionally unauthenticated depending on service exposure and configuration. CVE-2026-4480.py is another Samba RCE PoC using the spoolss/RPRN interface over the named pipe \\pipe\\spoolss. It defines custom NDR call structures for RpcStartDocPrinter, RpcWritePrinter, and RpcEndDocPrinter, opens a printer handle, submits a print job whose DocName is the attacker-controlled command, writes a few bytes of dummy print data, and ends the job to trigger execution. The vulnerable path is Samba's generic_job_submit when the print command contains %J and printing is configured unsafely. Main capability: remote arbitrary command execution through print job metadata injection. Overall, the repository's purpose is to demonstrate legacy Linux service exploitation paths discussed in the accompanying conference talk. The PoCs are operational rather than heavily weaponized: they provide direct exploitation and command execution/session access, but payload customization is manual through command-line arguments rather than modular framework support.
Repository contains a small Python proof-of-concept for CVE-2026-28372 targeting GNU inetutils telnetd (<= 2.7). Structure: (1) README.md describing the vulnerability (environment variables passed from telnetd to login(1)), the intended exploit chain (use Telnet NEW-ENVIRON to inject CREDENTIALS_DIRECTORY and provide a login.noauth file), and basic usage; (2) exploit.py implementing an automated trigger; (3) MIT license. Exploit behavior (exploit.py): it creates a temporary directory (prefix 'telnet_poc_'), writes a file named 'login.noauth' with content 'yes', sets the process environment variable CREDENTIALS_DIRECTORY to that directory, and launches the local 'telnet' client to the specified host (default 127.0.0.1) using subprocess.run(["telnet","-E","-K","-L",target], env=env). It then cleans up the temporary directory. Notable issues/limitations: the script does not actually implement Telnet NEW-ENVIRON option negotiation itself; it relies on the external telnet client and only sets the local process environment. Whether this environment is transmitted to telnetd depends on telnet client behavior and server negotiation; as written, it may not reliably perform the described environment injection. Additionally, the entry-point guard is buggy: it uses `if name == "__main__":` instead of `if __name__ == "__main__":`, so the script will raise a NameError and not run unless corrected. Overall maturity is best classified as a PoC rather than an operational exploit.
Repository contains a single Python PoC (exploit.py) plus README and MIT license. The README claims CVE-2026-28372 in GNU inetutils telnetd <= 2.7: telnetd allegedly forwards client-controlled environment variables (via Telnet NEW-ENVIRON) to login(1). By setting CREDENTIALS_DIRECTORY to an attacker-controlled directory containing login.noauth='yes', authentication can be bypassed, yielding a privileged session. Code behavior: exploit.py creates a temporary directory (prefix telnet_poc_), writes a login.noauth file with 'yes', sets the local process environment variable CREDENTIALS_DIRECTORY to that directory, and launches the system telnet client to connect to the target (default 127.0.0.1) using subprocess.run(["telnet","-E","-K","-L",target], env=env). It then cleans up the temp directory. Notable issues/limitations: the script does not implement Telnet NEW-ENVIRON negotiation itself; it only sets an environment variable for the local telnet client process. Whether that environment variable is actually transmitted to telnetd depends on the telnet client’s behavior and options (and may not occur as written). Additionally, the script has a bug in the entry-point guard: it uses `if name == "__main__":` instead of `if __name__ == "__main__":`, so it will not run when executed unless corrected. Overall, this is a basic PoC intended to demonstrate the exploit chain rather than a robust, weaponized exploit.
Repository contains a Python 3 proof-of-concept exploit for CVE-2026-28372 targeting GNU inetutils telnetd (<= 2.7) on Linux when paired with util-linux login(1) versions that support the login.noauth mechanism. The exploit is a local privilege escalation/authentication bypass chain: it creates an attacker-controlled credentials directory under the current user’s home (~/fake_creds_cve_2026_28372) and writes a login.noauth file containing 'yes'. It then connects to a telnetd service (default 127.0.0.1:23) using telnetlib and sends raw Telnet IAC negotiation bytes to use option 36 (NEW-ENVIRON) to inject environment variables USER (default root) and CREDENTIALS_DIRECTORY (pointing to the attacker directory). If telnetd passes these variables to login(1) and login honors login.noauth from that directory, authentication can be bypassed and the script drops into an interactive telnet session (tn.interact()), potentially yielding a root shell. Repo structure is minimal: one main exploit script (entry point) and a README documenting affected versions, prerequisites, usage flags (--host/--port/--user), and mitigations (sanitizing/unsetting CREDENTIALS_DIRECTORY, disabling telnet).
Repository contains a Python 3 proof-of-concept exploit for CVE-2026-28372 targeting GNU inetutils telnetd (<= 2.7) on Linux when paired with util-linux login(1) versions that support the login.noauth mechanism. Structure: (1) `GNU inetutils telnetd Privilege Escalation.py` is the sole exploit script and entry point; (2) `README.md` documents the vulnerability, prerequisites, and usage. Core capability: local privilege escalation to root by abusing telnet protocol option NEW-ENVIRON (option 36) to inject environment variables that telnetd passes to login(1). The script creates an attacker-controlled directory under the user’s home (`~/fake_creds_cve_2026_28372`) and writes `login.noauth` containing `yes`. It then connects to a telnetd endpoint (default 127.0.0.1:23), sends crafted IAC negotiation bytes and a NEW-ENVIRON subnegotiation that sets `USER` (default `root`) and `CREDENTIALS_DIRECTORY` to the attacker directory. If the target’s login(1) honors `CREDENTIALS_DIRECTORY` and reads `login.noauth=yes`, authentication can be bypassed and the script drops into an interactive telnet session (`tn.interact()`), intended to provide a root shell. Notable observables: network connection to configurable host/port (defaults localhost:23), creation of the credentials directory and `login.noauth` file in the invoking user’s home directory, and explicit injection of `USER` and `CREDENTIALS_DIRECTORY` via telnet NEW-ENVIRON.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A privilege escalation vulnerability in GNU telnetd that allows a local unprivileged user to gain root by abusing telnetd’s handling of the systemd CREDENTIALS_DIRECTORY environment variable passed to login.
Authentication bypass leading to unauthenticated root shell via environment-variable injection in GNU inetutils telnetd when it preserves environment for login(1) and fails to scrub CREDENTIALS_DIRECTORY.
A severe telnetd vulnerability in which a remote telnet client can set environment variables inherited by /usr/bin/login, abusing CREDENTIALS_DIRECTORY and login.noauth to bypass authentication and obtain a shell as any specified user, including root.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.