CVE-2026-28372 – Telnetd in GNU inetutils Privilege Escalation Vulnerability

CVE ID : CVE-2026-28372

Published : Feb. 27, 2026, 6:18 a.m. | 53 minutes ago

Description : telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.

Severity: 7.4 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه