Skip to content
COOEY

EXPOSURES › CVE-2026-24061

CVE-2026-24061

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-01-26 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-24061 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatchedauth-bypass

GNU InetUtils telnetd exposed to remote authentication bypass

GNU InetUtils' telnetd service had an unpatched argument injection vulnerability that allowed remote attackers to bypass authentication, potentially leading to unauthorized access.

Shame score — Critical remote code execution risk due to unpatched argument injection vulnerability.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.