CVE-2026-24061: GNU InetUtils Argument Injection Vulnerability
GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
Other sources
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GNU Inetutils (telnetd)from your environment.Discontinue use of the product and uninstall or disable telnetd if vendor mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24061?
CVE-2026-24061 is classified as a critical vulnerability due to its potential for remote authentication bypass.
How do I fix CVE-2026-24061?
To fix CVE-2026-24061, update GNU Inetutils to version 2.8 or later where the vulnerability has been addressed.
Which versions of GNU Inetutils are affected by CVE-2026-24061?
CVE-2026-24061 affects all versions of GNU Inetutils up to and including 2.7.
What impact does CVE-2026-24061 have on system security?
CVE-2026-24061 allows attackers to bypass authentication, potentially compromising the system's security.
Is CVE-2026-24061 exploited in the wild?
At this time, there is no public information indicating that CVE-2026-24061 is being actively exploited in the wild.