CVE-2026-28372
published 2026-02-27CVE-2026-28372: telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1)…
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.37%
29.6th percentile
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | inetutils | < inetutils 2:2.4-2+deb12u3 (bookworm) | inetutils 2:2.4-2+deb12u3 (bookworm) |
| gnu | inetutils | <= 2.7 | — |
| gnu | inetutils | >= 0 < 2:2.4-2+deb12u3 | 2:2.4-2+deb12u3 |
| gnu | inetutils | >= 0 < 2:2.6-3+deb13u2 | 2:2.6-3+deb13u2 |
| gnu | inetutils | >= 0 < 2:2.7-3 | 2:2.7-3 |
| ubuntu | inetutils | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-28372: telnetd in GNU inetutils through 2
osv·2026-02-27·CVSS 7.8
CVE-2026-28372 [HIGH] CVE-2026-28372: telnetd in GNU inetutils through 2
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.
GHSA
GHSA-j682-47rx-fxrp: telnetd in GNU inetutils through 2
ghsa_unreviewed·2026-02-27
CVE-2026-28372 [HIGH] CWE-829 GHSA-j682-47rx-fxrp: telnetd in GNU inetutils through 2
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.
Ubuntu
Inetutils vulnerabilities
vendor_ubuntu·2026-06-04·CVSS 7.8
CVE-2026-32746 [HIGH] Inetutils vulnerabilities
Title: Inetutils vulnerabilities
Summary: Several security issues were fixed in Inetutils.
It was discovered that the Inetutils telnet daemon incorrectly handled
the CREDENTIALS_DIRECTORY environment variable. An attacker could possibly
use this issue to escalate privileges. (CVE-2026-28372)
It was discovered that the Inetutils telnet daemon did not properly
validate buffer bounds when processing LINEMODE SLC suboptions. An attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. (CVE-2026-32746)
It was discovered that the Inetutils telnet client incorrectly handled the
NEW_ENVIRON SEND USERVAR option. An attacker could possibly use this issue
to read arbitrary environment variables. (CVE-2026-32772)
Instructions: In general, a standard system upd
Debian
CVE-2026-28372: inetutils - telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exp...
vendor_debian·2026·CVSS 7.4
CVE-2026-28372 [HIGH] CVE-2026-28372: inetutils - telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exp...
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.
Scope: local
bookworm: resolved (fixed in 2:2.4-2+deb12u3)
bullseye: open
forky: resolved (fixed in 2:2.7-3)
sid: resolved (fixed in 2:2.7-3)
trixie: resolved (fixed in 2:2.6-3+deb13u2)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-32772 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-32772 [HIGH] CVE-2026-32772 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32772 :
GNU InetUtils Telnet vulnerability analysis and mitigation
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
Source : NVD
## 3.4
Score
Published March 16, 2026
Severity LOW
CNA Score 3.4
Affected Technologies
GNU InetUtils Telnet
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
inetutils
cpe:2.3:a:gnu:inetutils
Sources
NVD
Debian 11 Severity LOW No Fix Added at: Mar 14, 2026
Debian 12, 13, 14 Severity LOW Has Fix Added at: Mar 14, 2026
Echo Severity LOW Has Fix Added at: Mar 14, 2026
Linux
Wiz
CVE-2026-28372 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-28372 [HIGH] CVE-2026-28372 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28372 :
NixOS vulnerability analysis and mitigation
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.
Source : NVD
## 7.8
Score
Published February 27, 2026
Severity HIGH
CNA Score 7.4
Affected Technologies
NixOS
Homebrew
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
inetutils
cpe:2.3:a:gnu:i
Wiz
CVE-2026-32746 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-32746 [HIGH] CVE-2026-32746 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32746 :
GNU InetUtils Telnet vulnerability analysis and mitigation
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.
Source : NVD
## 9.8
Score
Published March 13, 2026
Severity CRITICAL
CNA Score 9.8
High-profile Vulnerability Yes
Affected Technologies
GNU InetUtils Telnet
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
krb5-appl-clients
krb5-appl-servers
Sources
Debian 11 Severity CRITICAL No Fix Added at: Mar 14, 2026
Debian 12, 13, 14 Severity
https://git.hadrons.org/cgit/debian/pkgs/inetutils.git/commit/?id=3953943d8296310485f98963883a798545ab9a6chttps://lists.gnu.org/archive/html/bug-inetutils/2026-02/msg00000.htmlhttps://lists.gnu.org/archive/html/bug-inetutils/2026-02/msg00012.htmlhttps://www.openwall.com/lists/oss-security/2026/02/24/1http://www.openwall.com/lists/oss-security/2026/02/27/3http://www.openwall.com/lists/oss-security/2026/03/06/2http://www.openwall.com/lists/oss-security/2026/03/06/3http://www.openwall.com/lists/oss-security/2026/03/07/1http://www.openwall.com/lists/oss-security/2026/03/07/2
2026-02-27
Published