TL;DR: CVE-2026-24061 is a CVSS 9.8 flaw in GNU InetUtils telnetd that lets unauthenticated attackers reach an immediate root shell with a single command, with active exploitation already observed and public scans targeting exposed port 23, according to Orca Security. The issue shows that unauthenticated remote access services remain a direct identity risk, not just a network hygiene problem.
Editorial analysis by NHI Mgmt Group, based on content published by Orca Security: “GNU InetUtils telnetd Authentication Bypass Grants Instant Root Access”.
By the numbers:
- CVE-2026-24061 carries a CVSS score of 9.8, according to Orca Security.
- GreyNoise telemetry cited by Orca Security showed 18-21 unique IP addresses conducting automated exploitation scans within 24 hours of disclosure.
Key questions
Q: What breaks when telnetd can pass user input into login as a command flag?
A: The authentication boundary breaks.
Q: Why is exposed telnet such a serious access-control problem?
A: Because exposed telnet is not just an old transport, it is a remotely reachable administrative surface.
Q: What are the signs that telnetd exploitation is underway?
A: Look for telnet sessions negotiating NEW_ENVIRON with suspicious USER values, especially dash-prefixed arguments, and for root shell processes spawned by telnetd without a normal authentication flow.
Practitioner guidance
- Disable telnetd on every reachable host Stop and disable telnetd on systems that still run it, then verify that no management workflow depends on TCP port 23 for administrative access.
- Block external access to port 23 Remove internet exposure at firewalls, security groups, and network ACLs so unauthenticated remote sessions cannot reach the service even before patching is complete.
- Patch or remove affected inetutils packages Upgrade vulnerable GNU InetUtils telnetd installations to fixed releases, or uninstall the package entirely where the service is not essential.
Bottom line: CVE-2026-24061 shows that a remote access daemon can become a direct root shell path when it accepts attacker-controlled arguments as part of authentication flow.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Argument injection at the login boundary is the real failure, not telnet as a protocol. The vulnerable trust decision happens when user-controlled environment data is converted into a login command line. That means the security boundary is not the socket, but the point where remote input becomes privileged execution. Practitioners should read this as a command-construction failure in a remote access service, not a simple patch-ticket item.
A question worth separating out:
Q: Should organisations keep telnetd running if it is patched?
A: Usually no. If an unauthenticated flaw can convert a remote connection into root access, the safer decision is to remove telnetd wherever possible and reserve privileged administration for encrypted, accountable remote access methods with stronger session controls.
👉 Read our full editorial: CVE-2026-24061 shows how telnetd turns input into root access