GNU InetUtils Argument Injection Vulnerability

GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.

Published 26 Aug 2026Updated 26 Aug 20261704 sources
CVSS 9.8 CRITICAL✓ VERIFIED REFERENCE△ CISA KEV

What happened

GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.

Affected versions

InetUtils: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 52524GNU InetUtils 2.6 - Telnetd Remote Privilege Escalationaliguliyev2026-04-29VerifiedCVE-Intel · obrunolima1910/CVE-2026-24061🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.BypassPythonCRITICALAnalyzed★ 0⑂ 0EPSS 97.88%CVE data: CNACode indexedUpdated 26 Aug 2026Tags: agent, auth, book, computer-vision, cv, deep-learning, gluon, image-classificationobrunolima19102026-02-03CandidateCVE-Intel · jacubes/CVE-2026-24061CVE-2026-24061 exploit PoCPoCPythonCRITICALAnalyzed★ 824⑂ 15EPSS 97.88%CVE data: CNACode indexedUpdated 24 Aug 2026Tags: cve, cve-2026-24061, cve-poc, exploit, vulnerabilityjacubes2026-03-08CandidateCVE-Intel · SafeBreach-Labs/CVE-2026-24061Exploitation of CVE-2026-24061ExploitPythonCRITICALAnalyzed★ 207⑂ 47EPSS 97.88%CVE data: CNACode indexedUpdated 24 Aug 2026SafeBreach-Labs2026-01-22CandidateCVE-Intel · franckferman/CVE-2026-24061GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.InjectionPythonCRITICALAnalyzed★ 4⑂ 0EPSS 97.88%CVE data: CNACode indexedUpdated 21 Aug 2026Tags: authentication-bypass, cve, cve-2026-24061, cves, exploit, exploitation, exploiting, inetutilsfranckferman2026-02-02CandidateCVE-Intel · ekomsSavior/telnet_scanscanner/exploiter CVE-2026-24061 & CVE-2026-32746ExploitPythonCRITICALAnalyzed★ 12⑂ 6EPSS 97.88%CVE data: CNACode indexedUpdated 19 Aug 2026ekomsSavior2026-03-26CandidateCVE-Intel · 0p5cur/CVE-2026-24061-POCCVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the vulnerability from 2015 onwards.RCEPythonCRITICALAnalyzed★ 7⑂ 3EPSS 97.88%CVE data: CNACode indexedUpdated 11 Aug 2026Tags: cve, cve-2026-24061, poc, rce, root, telnet, telnet-server, unauthenticated-rce0p5cur2026-01-24CandidateCVE-Intel · s-vx/CVE-2026-24061Auth Bypass in inetutils-telnetdBypassPythonCRITICALAnalyzed★ 0⑂ 0EPSS 97.88%CVE data: CNACode indexedUpdated 25 Jul 2026s-vx2026-07-25CandidateCVE-Intel · Lingzesec/CVE-2026-24061-GUICVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具ExploitPythonCRITICALAnalyzed★ 17⑂ 1EPSS 97.88%CVE data: CNACode indexedUpdated 24 Jul 2026Lingzesec2026-01-26CandidatePoC-in-GitHub · leonjza/inetutils-telnetd-auth-bypassA small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.★ 12leonjza2026-01-21CandidatePoC-in-GitHub · duy-31/CVE-2026-24061---telnetdBypass d’authentification Telnet menant à un accès root★ 2duy-312026-01-22CandidatePoC-in-GitHub · TryA9ain/CVE-2026-24061CVE-2026-24061 Batch Scanning Tool★ 10TryA9ain2026-01-22CandidatePoC-in-GitHub · parameciumzhang/Tell-Me-Root基于cve-2026-24061 telnet远程认证绕过漏洞的批量检测利用工具★ 21parameciumzhang2026-01-22CandidatePoC-in-GitHub · Chocapikk/CVE-2026-24061★ 12Chocapikk2026-01-22CandidatePoC-in-GitHub · JayGLXR/CVE-2026-24061-POC★ 67JayGLXR2026-01-22CandidatePoC-in-GitHub · h3athen/CVE-2026-24061CVE-2026-24061 - Exploit★ 8h3athen2026-01-22CandidatePoC-in-GitHub · xuemian168/CVE-2026-24061★ 3xuemian1682026-01-23CandidatePoC-in-GitHub · monstertsl/CVE-2026-24061CVE-2026-24061 漏洞检测工具★ 1monstertsl2026-01-23CandidatePoC-in-GitHub · r00tuser111/CVE-2026-24061CVE-2026-24061 环境★ 0r00tuser1112026-01-23CandidatePoC-in-GitHub · balgan/CVE-2026-24061inetutils-telnetd Authentication Bypass - working★ 3balgan2026-01-23CandidatePoC-in-GitHub · sh4den/CVE-2026-24061Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers to gain instant root shell access via malicious NEW_ENVIRON telnet option exploitation.★ 6sh4den2026-01-23CandidatePoC-in-GitHub · z3n70/CVE-2026-24061★ 0z3n702026-01-24CandidatePoC-in-GitHub · Mr-Zapi/CVE-2026-24061Nuclei template for CVE-2026-24061★ 1Mr-Zapi2026-01-24CandidatePoC-in-GitHub · midox008/CVE-2026-24061GNU Inetutils telnetd Remote Authentication Bypass★ 0midox0082026-01-24CandidatePoC-in-GitHub · BrainBob/CVE-2026-24061★ 0BrainBob2026-01-24CandidatePoC-in-GitHub · BrainBob/Telnet-TestVuln-CVE-2026-24061★ 0BrainBob2026-01-24CandidatePoC-in-GitHub · shivam-bathla/CVE-2026-24061-setupDocker setup for CVE-2026-24061★ 4shivam-bathla2026-01-24CandidatePoC-in-GitHub · madfxr/Twenty-Three-ScannerCVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass★ 4madfxr2026-01-24CandidatePoC-in-GitHub · Alter-N0X/CVE-2026-24061-POCCVE-2026-24061 - GNU InetUtils telnetd authentication bypass POC + Docker lab environment for testing★ 0Alter-N0X2026-01-24CandidatePoC-in-GitHub · typeconfused/CVE-2026-24061GNU telnetd service from GNU InetUtils authentication-bypass★ 0typeconfused2026-01-25CandidatePoC-in-GitHub · Mefhika120/Ashwesker-CVE-2026-24061CVE-2026-24061★ 0Mefhika1202026-01-25CandidatePoC-in-GitHub · infat0x/CVE-2026-24061CVE-2026-24061 PoC★ 1infat0x2026-01-25CandidatePoC-in-GitHub · ms0x08-dev/CVE-2026-24061-POC★ 0ms0x08-dev2026-01-25CandidatePoC-in-GitHub · punitdarji/telnetd-cve-2026-24061★ 0punitdarji2026-01-26CandidatePoC-in-GitHub · XsanFlip/CVE-2026-24061-ScannerCVE-2026-24061-Scanner by XsanLahci★ 0XsanFlip2026-01-26CandidatePoC-in-GitHub · LucasPDiniz/CVE-2026-24061Vulnerability in GNU InetUtils telnetd Enables Remote Root Access★ 0LucasPDiniz2026-01-26CandidatePoC-in-GitHub · FurkanKAYAPINAR/CVE-2026-24061-telnet2root★ 1FurkanKAYAPINAR2026-01-27CandidatePoC-in-GitHub · androidteacher/CVE-2026-24061-PoC-Telnetd★ 0androidteacher2026-01-27CandidatePoC-in-GitHub · cumakurt/tscanTelnetd Auth Bypass Scanner (CVE-2026-24061) A Python-based scanner for detecting and exploiting the CVE-2026-24061 vulnerability in GNU Inetutils telnetd services. This tool scans IP addresses or networks for vulnerable telnetd services that allow authentication bypass leading to root shell access.★ 1cumakurt2026-01-27CandidatePoC-in-GitHub · novitahk/Exploit-CVE-2026-24061Payload CVE-2026-24061★ 0novitahk2026-01-27CandidatePoC-in-GitHub · Gabs-hub/CVE-2026-24061_LabLab to show the CVE-2026-24061★ 0Gabs-hub2026-01-28CandidatePoC-in-GitHub · MY0723/GNU-Inetutils-telnet-CVE-2026-24061-GNU Inetutils telnet远程认证绕过漏洞(CVE-2026-24061),该漏洞源于 GNU Inetutils telnetd 组件中对环境变量处理不当,攻击者可利用该漏洞,通过构造恶意的 USER 环境变量并发送至受影响的 telnet 服务,触发认证绕过机制,进而实现无需密码直接获取root权限。★ 1MY07232026-01-28CandidatePoC-in-GitHub · 0x7556/CVE-2026-24061CVE-2026-24061 Telnet RCE Exploit For Linux MacOS Windows★ 00x75562026-01-28CandidatePoC-in-GitHub · Parad0x7e/CVE-2026-24061★ 0Parad0x7e2026-01-28CandidatePoC-in-GitHub · dotelpenguin/telnetd_CVE-2026-24061_testerChecks for CVE-2026-24061 Telnetd exploit★ 1dotelpenguin2026-01-28CandidatePoC-in-GitHub · JakeSwiz/telnet-inetutils-auth-bypass-CVE-2026-24061This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is going on right now. Why people are still using Telnet... beyond me.★ 1JakeSwiz2026-01-31CandidatePoC-in-GitHub · buzz075/CVE-2026-24061Scanner for CVE-2026-24061★ 0buzz0752026-01-31CandidatePoC-in-GitHub · X-croot/CVE-2026-24061_POCPOC Script for CVE-2026-24061 (GNU Telnetd Exploit)★ 2X-croot2026-02-01CandidatePoC-in-GitHub · SeptembersEND/CVE--2026-24061A docker image for CVE-2026-24061 in InetUtils telnetd.★ 0SeptembersEND2026-02-02CandidatePoC-in-GitHub · lavabyte/telnet-CVE-2026-24061★ 0lavabyte2026-02-04CandidatePoC-in-GitHub · canpilayda/inetutils-telnetd-cve-2026-24061★ 0canpilayda2026-02-04CandidatePoC-in-GitHub · killsystema/scan-cve-2026-24061★ 0killsystema2026-02-05CandidatePoC-in-GitHub · nrnw/CVE-2026-24061-GNU-inetutils-Telnet-DetectorA passive detection tool for identifying potential exposure to CVE-2026-24061 in GNU inetutils telnet installations★ 0nrnw2026-02-06CandidatePoC-in-GitHub · scumfrog/cve-2026-24061CVE-2026-24061 PoC★ 0scumfrog2026-02-06CandidatePoC-in-GitHub · tiborscholtz/CVE-2026-24061A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, which contains automatic username injection using the NEW-ENVIRON option.★ 0tiborscholtz2026-02-14CandidatePoC-in-GitHub · athack-ctf/chall2026-telneted[AtHack 2026] Pwn challenge about telnetd CVE-2026-24061★ 0athack-ctf2026-02-15CandidatePoC-in-GitHub · mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-★ 0mbanyamer2026-02-18CandidatePoC-in-GitHub · setuju/telnetdIdk what to do here, ill edit soon, but its for the telnetd CVE-2026-24061★ 1setuju2026-03-03CandidatePoC-in-GitHub · 0xBlackash/CVE-2026-24061CVE-2026-24061★ 10xBlackash2026-03-09CandidatePoC-in-GitHub · HD0x01/CVE-2026-24061-NSEThe script performs a full Telnet negotiation mirroring the exact byte sequence of a real telnet -a client session.★ 0HD0x012026-03-16CandidatePoC-in-GitHub · przemytn/CVE-2026-24061CVE-2026-24061 PoC - telnetd auth bypass★ 0przemytn2026-03-18CandidatePoC-in-GitHub · ahmadsadeeq/TelnetdBypass-CVE-2026-24061 — GNU InetUtils Telnetd Authentication Bypass Scanner★ 0ahmadsadeeq2026-06-01CandidatePoC-in-GitHub · tc4dy/CVE-2026-24061-PoC-Exploit🚀 CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass Exploit - Full Control 💥 CRLF injection via NEW_ENVIRON leads to auth bypass & instant root shell. ✅ Single/Mass exploitation, multi-threading, custom port/user, pipe mode, session keep-alive, colored output, retries, timeout support. ⚡ Python & Bash versions. Critical CVSS 9.8.★ 6tc4dy2026-06-06CandidatePoC-in-GitHub · K3ysTr0K3R/CVE-2026-24061A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass★ 3K3ysTr0K3R2026-06-08CandidatePoC-in-GitHub · anxs3c/CVE-2026-24061-GNU-InetUtils-telnetdGNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability★ 0anxs3c2026-06-08CandidatePoC-in-GitHub · akpmarcelin/CVE-2026-24061-lab★ 0akpmarcelin2026-06-17CandidatePoC-in-GitHub · kyukazamiqq/CVE-2026-24061★ 0kyukazamiqq2026-06-27CandidatePoC-in-GitHub · harygovind/CVE-2026-24061CVE-2026-24061-PoC★ 0harygovind2026-07-06CandidatePoC-in-GitHub · stoerti2/AbyssalAbyssal is a high-performance Telnet vulnerability scanner for CVE-2026-24061, delivering root shells on vulnerable systems with false-positive detection.★ 0stoerti22026-07-10CandidatePoC-in-GitHub · iLokaas/CVE-2026-24061-payloadA PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass★ 0iLokaas2026-08-28CandidatePoC-in-GitHub · Ish3ng0m4/CVE-2026-24061-TelnetdCVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass★ 0Ish3ng0m42026-09-01CandidatePoC-in-GitHub · skyejacobson/CyberhawksLab-telnetCVEWriteup/finding of CVE-2026-24061 within the Cyberhawks lab★ 0skyejacobson2026-09-08Candidate