CVE-2026-28372 – Telnetd in GNU inetutils Privilege Escalation Vulnerability
CVE ID : CVE-2026-28372
Published : Feb. 27, 2026, 6:18 a.m. | 53 minutes ago
Description : telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…