← Vulnerability feed

Vulnerability record · CVE-2026-28372 · published 27 February 2026

CVE-2026-28372: Gnu inetutils inclusion from untrusted sphere vulnerability

Gnu · Inetutils

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.

7.8 CVSS 3.1 High EPSS 0.20% · top 91.2% CWE-829 · Inclusion from untrusted sphere
7.8CVSS 3.1 base score
0.20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-28372 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed10.0CVE-2011-4862telnetd encryption key buffer overflow allows remote code executionA buffer overflow in libtelnet/encrypt.c in telnetd affects FreeBSD 7.3 through 9.0, MIT krb5-appl 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU …EPSS 95%analysed9.8CVE-2026-32746Gnu inetutils classic buffer overflow vulnerabilitytelnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does …EPSS 2.4%7.8CVE-2023-40303Gnu inetutils unchecked return value vulnerabilityGNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rs…EPSS 0.41%7.5CVE-2022-39028Gnu inetutils null pointer dereference vulnerabilitytelnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In…EPSS 2.1%6.5CVE-2021-40491Gnu inetutils insufficient verification of data authenticity vulnerabilityThe ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. Th…EPSS 1.0%4.7CVE-2026-32772Gnu inetutils vulnerabilitytelnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.EPSS 0.27%9.8CVE-2026-0770Langflow validate endpoint exec_globals remote code executionLangflow mishandles the exec_globals parameter passed to its validate endpoint, allowing functionality from an untrusted control sphere to be include…KEVEPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2026-28372), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.