CVE-2026-24061

critical

Description

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

References

https://github.com/cipher131/cve-exploit-mapper

https://github.com/0p5cur/CVE-2026-62737-POC

https://github.com/s-vx/CVE-2026-24061

https://github.com/stoerti2/Abyssal

https://github.com/Hector-Abarca/realrisk-checks

https://github.com/Cosm3No1de/htb-orion-writeup

https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit

https://github.com/akpmarcelin/CVE-2026-24061-lab

https://github.com/tc4dy/CVE-2026-24061-PoC-Exploit

https://github.com/ahmadsadeeq/TelnetdBypass-

https://github.com/1392081456/sigma-detection-rules

https://github.com/tc4dy/CVE-2026-0073-PoC-Exploit

https://github.com/tc4dy/CVE-2026-41940-PoC-Exploit

https://github.com/1392081456/ctf-notes

https://github.com/RStephanH/vuln-deb

https://github.com/Risma2025/CVE-2026-24061-GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability

https://github.com/mrhenrike/EmbedXPL-Forge

https://github.com/ekomsSavior/telnet_scan

https://github.com/przemytn/CVE-2026-24061

https://github.com/HD0x01/CVE-2026-24061-NSE

https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS

https://github.com/0xAshwesker/CVE-2026-24061

https://github.com/anacarsi/CVEs-exploit-2026

https://github.com/Remnant-DB/CVE-2026-24061

https://github.com/setuju/telnetd

https://github.com/athack-ctf/chall2026-telneted

https://github.com/tiborscholtz/CVE-2026-24061

https://github.com/nrnw/CVE-2026-24061-GNU-inetutils-Telnet-Detector

https://github.com/killsystema/scan-cve-2026-24061

https://github.com/canpilayda/inetutils-telnetd-cve-2026-24061

https://github.com/lavabyte/telnet-CVE-2026-24061

https://github.com/obrunolima1910/obrunolima1910.github.io

https://github.com/obrunolima1910/CVE-2026-24061

https://github.com/Moxxic1/moxxic1.github.io

https://github.com/Moxxic1/Tell-Me-Root

https://github.com/Good123321-bot/good123321-bot.github.io

https://github.com/olatunbosunoyeleke94/telnet-sec

https://github.com/SeptembersEND/CVE--2026-24061

https://github.com/franckferman/CVE_2026_24061_PoC

https://github.com/franckferman/CVE_2026_24061

https://github.com/XiaomingX/data-cve-poc-py-v1

https://github.com/ridpath/Terrminus-CVE-2026-2406

https://github.com/dotelpenguin/telnetd_CVE-2026-24061_tester

https://github.com/Parad0x7e/CVE-2026-24061

https://github.com/0x7556/CVE-2026-24061

https://github.com/hilwa24/CVE-2026-24061

https://github.com/MY0723/GNU-Inetutils-telnet-CVE-2026-24061-

https://github.com/Gabs-hub/CVE-2026-24061_Lab

https://github.com/novitahk/Exploit-CVE-2026-24061

https://github.com/cumakurt/tscan

https://github.com/FurkanKAYAPINAR/CVE-2026-24061-telnet2root

https://github.com/LucasPDiniz/CVE-2026-24061

https://github.com/Lingzesec/cve-2026-24061-GUI

https://github.com/Lingzesec/CVE-2026-24061-GUI

https://github.com/XsanFlip/CVE-2026-24061-Scanner

https://github.com/punitdarji/telnetd-cve-2026-24061

https://github.com/ms0x08-dev/CVE-2026-24061-POC

https://github.com/typeconfused/CVE-2026-24061

https://github.com/DeadlyHollows/CVE-2026-24061-setup

https://github.com/BrainBob/Telnet-TestVuln-CVE-2026-24061

https://github.com/BrainBob/CVE-2026-24061

https://github.com/Mr-Zapi/CVE-2026-24061

https://github.com/z3n70/CVE-2026-24061

https://github.com/splinterlabs/osint-agent-public

https://github.com/r00tuser111/CVE-2026-24061

https://github.com/m3ngx1ng/cve_2026_24061_cli

https://github.com/Ashwesker/Ashwesker-CVE-2026-24061

https://github.com/monstertsl/CVE-2026-24061

https://github.com/h3athen/CVE-2026-24061

https://github.com/SafeBreach-Labs/CVE-2026-24061

https://github.com/TryA9ain/CVE-2026-24061

https://github.com/duy-31/CVE-2026-24061---telnetd

https://github.com/leonjza/inetutils-telnetd-auth-bypass

https://github.com/Hatchepsoute/sigma-rules

https://www.openwall.com/lists/oss-security/2026/01/20/8

https://www.openwall.com/lists/oss-security/2026/01/20/2

https://www.gnu.org/software/inetutils/

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24061

https://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.html

https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7b

https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc

http://www.openwall.com/lists/oss-security/2026/01/22/1

Details

Source: Mitre, NVD

Published: 2026-01-21

Updated: 2026-02-11

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.98064

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability Being Monitored