CVE-2026-28372 - Telnetd in GNU inetutils Privilege Escalation Vulnerability

CVE-2026-28372 - Telnetd in GNU inetutils Privilege Escalation Vulnerability

CVE ID : CVE-2026-28372 Published : Feb. 27, 2026, 5:28 a.m. | 51 minutes ago Description : telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Feb. 27, 2026
Affected Product: linux
Attack Vector: local
Impact: privilege escalation