CVE-2026-28372General(gnu / inetutils)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • inetutils

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-27); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
inetutils

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-27: 3Mentions · 2026-02-28: 1Mentions · 2026-03-04: 1Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-04: 102-2702-2803-04
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-273
Disclosure1General2
2026-02-281
Disclosure1
2026-03-041
General1
Full discourse5 posts
  • NanoVMs@nanovms
    General

    a 27 year old regression of CVE-1999-0073 now has a new cve CVE-2026-28372 (this is a new/diff one than from jan) the lesson here is not "jUsT Us# sSh!!!@" 1) ban users 2) ban shells 3) use unikernels https://t.co/hGMbYphRRi

    Post summary

    The tweet references a new CVE and a link but provides no technical details, exploitation evidence, or mitigation guidance.

    03061410
    2.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28372 Privilege Escalation in GNU inetutils telnetd Through 2.7 via util-linux 2.40 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28372

    Post summary

    The post announces a privilege escalation vulnerability in GNU inetutils telnetd (through version 2.7) via util-linux 2.40, with no PoC, exploit, or patch details provided.

    0101196
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-28372 (CVSS:7.4, HIGH) is Analyzed. telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service creden..https://nvd.nist.gov/vuln/detail/CVE-2026-28372 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-28372, noting its CVSS score and that it allows privilege escalation via telnetd in GNU inetutils, but does not provide PoC, exploit code, or patch information.

    0000036
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28372 telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementa… https://www.cve.org/CVERecord?id=CVE-2026-28372

    Post summary

    The text announces CVE-2026-28372, detailing a privilege‑escalation flaw in GNU inetutils’ telnetd via abused systemd service credentials, with no PoC, exploit, or patch information provided.

    00000103
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28372 - Telnetd in GNU inetutils Privilege Escalation Vulnerability Intel Report: https://ift.tt/9RPOYpx

    Post summary

    An alert references CVE-2026-28372, a privilege escalation flaw in Telnetd of GNU inetutils, but provides no PoC, exploit, patch, or active exploitation details.

    0000013
    341 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuinetutils---

Explore more