CVE-2026-28372 Details
Description
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.
A privilege escalation vulnerability has been identified in the Telnet daemon (telnetd) of GNU Inetutils, affecting versions through 2.7. This vulnerability arises from the introduction of systemd service credentials support in the login implementation of util-linux, starting with version 2.40. The issue allows an unprivileged local user to bypass authentication and gain unauthorized access by manipulating the CREDENTIALS_DIRECTORY environment variable. By creating a specific file in a designated directory, the user can exploit telnetd's ability to pass environment variables, leading to elevated privileges.
Users can update to the latest version of GNU Inetutils, where this vulnerability has been addressed. Instructions for updating can be found in the GNU Inetutils documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/02/27/3 | CVE | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/06/2 | CVE | |
| http://www.openwall.com/lists/oss-security/2026/03/06/3 | CVE | |
| http://www.openwall.com/lists/oss-security/2026/03/07/1 | CVE | |
| http://www.openwall.com/lists/oss-security/2026/03/07/2 | CVE | |
| https://git.hadrons.org/cgit/debian/pkgs/inetutils.git/commit/?id=3953943d8296310485f98963883a798545ab9a6c | [email protected] | Patch |
| https://lists.gnu.org/archive/html/bug-inetutils/2026-02/msg00000.html | [email protected] | ExploitMailing ListThird Party Advisory |
| https://lists.gnu.org/archive/html/bug-inetutils/2026-02/msg00012.html | [email protected] | Mailing ListThird Party Advisory |
| https://www.openwall.com/lists/oss-security/2026/02/24/1 | [email protected] | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu inetutils | <= 2.7 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 7, 2026 | CVE Modified | CVE |
| Mar 6, 2026 | CVE Modified | CVE |
| Mar 2, 2026 | Initial Analysis | [email protected] |
| Feb 27, 2026 | CVE Modified | CVE |
| Feb 27, 2026 | New CVE Received | [email protected] |