Improper Neutralization of Argument Delimiters in a Command in Inetutils - GNU network utilities - CVE-2026-24061
Published: January 22, 2026 / Updated: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation when processing attacker-controlled USER environment variable. A remote non-authenticated attacker can simply connect to the remote server with a specially crafted environment variable and obtain root privileges.
Exploitation example:
USER='-f root' telnet -a <host>
Affected software
Gentoo Linux
Debian Linux
Ubuntu
LANTIME Operating System Firmware (LTOS)
inetutils (Ubuntu package)
inetutils (Debian package)
net-misc/inetutils
How to mitigate CVE-2026-24061
LANTIME Operating System Firmware (LTOS) - addressed in versions 7.10.009, 7.10.012
inetutils (Ubuntu package) - addressed in versions 2:1.9.4-1ubuntu0.1~esm5, 2:1.9.4-3ubuntu0.1+esm4, 2:1.9.4-11ubuntu0.2+esm3, 2:2.2-2ubuntu0.2, 2:2.5-3ubuntu4.1, 2:2.6-1ubuntu3.1
inetutils (Debian package) - addressed in versions 2:2.4-2+deb12u2, 2:2.6-3+deb13u1
net-misc/inetutils - update to 2.7
Links to Public Exploits and PoC-codes
- Exploit #12995 - CVE-2026-24061-payload (A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass ) (August 31, 2026)
- Exploit #12990 - CVE-2026-24061 (A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass) (August 31, 2026)
- Exploit #12958 - CVE-2026-24061 (CVE-2026-24061 exploit PoC) (August 21, 2026)
- Exploit #12523 - CVE_2026_24061 ( GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.) (April 1, 2026)
- Exploit #12442 - CVE-2026-24061 (A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, which contains automatic username injection using the NEW-ENVIRON option.) (February 27, 2026)
- Exploit #12393 - GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061 (February 11, 2026)
- Exploit #12362 - CVE-2026-24061 (CVE-2026-24061 - Exploit) (February 6, 2026)
- Exploit #12360 - cve-2026-24061-exploit-tool (CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具) (February 6, 2026)
- Exploit #12355 - CVE-2026-24061 (Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers to gain instant root shell access via malicious NEW_ENVIRON telnet option exploitation.) (February 6, 2026)
External References
Related Security Bulletins
- Multiple vulnerabilities in Inetutils - GNU network utilities
- Debian update for inetutils
- Gentoo update for inetutils
- Ubuntu update for inetutils
- Ubuntu update for inetutils
- Meinberg LANTIME firmware update for third-party components
- Multiple vulnerabilities in Meinberg LANTIME Operating System Firmware