CVE-2026-24061: GNU InetUtils Argument Injection Vulnerability

Published Jan 21, 2026
·
Updated

GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.

Other sources

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

MITRE

Affected Software

4 affected components
GNU InetUtils<=2.7
GNU InetUtils
GNU InetUtils>=1.9.3<=2.7
Debian Debian Linux=11.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove GNU Inetutils (telnetd) from your environment.

    Discontinue use of the product and uninstall or disable telnetd if vendor mitigations are unavailable.

  2. Compensating control

    Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services.

Event History

Jan 21, 2026
CVE Published
via MITRE·06:42 AM
Data Sourced
via MITRE·06:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 22, 2026
News Published
via The Register·12:13 PM
News Published
via The Register·12:17 PM
Jan 23, 2026
News Published
via BleepingComputer·04:21 PM
News Published
via BleepingComputer·04:23 PM
Jan 26, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
News Published
via BleepingComputer·03:19 PM
Feb 11, 2026
News Published
via The Register·03:41 PM
Feb 14, 2026
News Published
via BleepingComputer·04:02 PM
Apr 29, 2026
Exploit Published
via ExploitDB·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-24061?

CVE-2026-24061 is classified as a critical vulnerability due to its potential for remote authentication bypass.

2

How do I fix CVE-2026-24061?

To fix CVE-2026-24061, update GNU Inetutils to version 2.8 or later where the vulnerability has been addressed.

3

Which versions of GNU Inetutils are affected by CVE-2026-24061?

CVE-2026-24061 affects all versions of GNU Inetutils up to and including 2.7.

4

What impact does CVE-2026-24061 have on system security?

CVE-2026-24061 allows attackers to bypass authentication, potentially compromising the system's security.

5

Is CVE-2026-24061 exploited in the wild?

At this time, there is no public information indicating that CVE-2026-24061 is being actively exploited in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203