CVE-2026-32772
published 2026-03-16CVE-2026-32772: telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
PriorityP426medium4.7CVSS 3.1
AVNACLPRNUIRSCCLINAN
EPSS
0.19%
8.5th percentile
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | inetutils | < inetutils 2:2.4-2+deb12u3 (bookworm) | inetutils 2:2.4-2+deb12u3 (bookworm) |
| gnu | inetutils | <= 2.7 | — |
| gnu | inetutils | >= 0 < 2:2.4-2+deb12u3 | 2:2.4-2+deb12u3 |
| gnu | inetutils | >= 0 < 2:2.6-3+deb13u3 | 2:2.6-3+deb13u3 |
| gnu | inetutils | >= 0 < 2:2.7-5 | 2:2.7-5 |
| ubuntu | inetutils | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
osv3.4LOW
vendor_ubuntu7.8HIGH
vendor_debian3.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU inetutils up to 2.7 telnet resource transfer (EUVD-2026-12154 / Nessus ID 302261)
vuldb·2026-05-05·CVSS 4.7
CVE-2026-32772 [MEDIUM] GNU inetutils up to 2.7 telnet resource transfer (EUVD-2026-12154 / Nessus ID 302261)
A vulnerability was found in GNU inetutils up to 2.7 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component telnet. The manipulation results in incorrect resource transfer.
This vulnerability is cataloged as CVE-2026-32772. The attack may be launched remotely. There is no exploit available.
GHSA
GHSA-5p6r-4c7p-96fh: telnet in GNU inetutils through 2
ghsa_unreviewed·2026-03-16
CVE-2026-32772 [LOW] CWE-669 GHSA-5p6r-4c7p-96fh: telnet in GNU inetutils through 2
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
OSV
CVE-2026-32772: telnet in GNU inetutils through 2
osv·2026-03-16·CVSS 3.4
CVE-2026-32772 [LOW] CVE-2026-32772: telnet in GNU inetutils through 2
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
Ubuntu
Inetutils vulnerabilities
vendor_ubuntu·2026-06-04·CVSS 7.8
CVE-2026-32746 [HIGH] Inetutils vulnerabilities
Title: Inetutils vulnerabilities
Summary: Several security issues were fixed in Inetutils.
It was discovered that the Inetutils telnet daemon incorrectly handled
the CREDENTIALS_DIRECTORY environment variable. An attacker could possibly
use this issue to escalate privileges. (CVE-2026-28372)
It was discovered that the Inetutils telnet daemon did not properly
validate buffer bounds when processing LINEMODE SLC suboptions. An attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. (CVE-2026-32746)
It was discovered that the Inetutils telnet client incorrectly handled the
NEW_ENVIRON SEND USERVAR option. An attacker could possibly use this issue
to read arbitrary environment variables. (CVE-2026-32772)
Instructions: In general, a standard system upd
Debian
CVE-2026-32772: inetutils - telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment...
vendor_debian·2026·CVSS 3.4
CVE-2026-32772 [LOW] CVE-2026-32772: inetutils - telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment...
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
Scope: local
bookworm: resolved (fixed in 2:2.4-2+deb12u3)
bullseye: open
forky: resolved (fixed in 2:2.7-5)
sid: resolved (fixed in 2:2.7-5)
trixie: resolved (fixed in 2:2.6-3+deb13u3)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-32772 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-32772 [HIGH] CVE-2026-32772 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32772 :
GNU InetUtils Telnet vulnerability analysis and mitigation
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
Source : NVD
## 3.4
Score
Published March 16, 2026
Severity LOW
CNA Score 3.4
Affected Technologies
GNU InetUtils Telnet
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
inetutils
cpe:2.3:a:gnu:inetutils
Sources
NVD
Debian 11 Severity LOW No Fix Added at: Mar 14, 2026
Debian 12, 13, 14 Severity LOW Has Fix Added at: Mar 14, 2026
Echo Severity LOW Has Fix Added at: Mar 14, 2026
Linux
Wiz
CVE-2026-32746 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-32746 [HIGH] CVE-2026-32746 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32746 :
GNU InetUtils Telnet vulnerability analysis and mitigation
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.
Source : NVD
## 9.8
Score
Published March 13, 2026
Severity CRITICAL
CNA Score 9.8
High-profile Vulnerability Yes
Affected Technologies
GNU InetUtils Telnet
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
krb5-appl-clients
krb5-appl-servers
Sources
Debian 11 Severity CRITICAL No Fix Added at: Mar 14, 2026
Debian 12, 13, 14 Severity
2026-03-16
Published