CVE-2026-28372: Telnetd Vulnerability port
Last updated 8 June 2026
Other sources
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALSDIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28372?
CVE-2026-28372 is a high-severity vulnerability that allows for privilege escalation through a flaw in telnetd in GNU inetutils.
How do I fix CVE-2026-28372?
To fix CVE-2026-28372, users should upgrade to version 2.7 or later of the GNU inetutils package.
Who is affected by CVE-2026-28372?
CVE-2026-28372 affects all versions of GNU inetutils prior to 2.7.
What is the nature of the attack for CVE-2026-28372?
CVE-2026-28372 can be exploited by abusing systemd service credentials support, allowing unauthorized access to higher privileges.
Is CVE-2026-28372 related to any specific configuration?
Yes, CVE-2026-28372 is related to the client control over the CREDENTIALS_DIRECTORY environment variable.