CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Unauthenticated Remote Root Code Execution Vulnerability in GNU InetUtils Telnetd (CVE-2026-32746)

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

An unauthenticated remote attacker can execute arbitrary code with root privileges via CVE-2026-32746, a critical out-of-bounds write vulnerability in the GNU InetUtils telnet daemon (telnetd) affecting versions through 2.7. The flaw resides in the LINEMODE Set Local Characters (SLC) suboption handler during the initial Telnet handshake, enabling exploitation before any login prompt appears. Successful exploitation requires only a single connection to port 23 and does not require credentials, user interaction, or special network positioning, leading to potential full system compromise.

Timeline

  1. 18.03.2026 07:06 1 articles · 2h ago

    Critical unauthenticated RCE vulnerability (CVE-2026-32746) disclosed in GNU InetUtils telnetd

    An unauthenticated remote attacker can achieve arbitrary code execution with root privileges via CVE-2026-32746, an out-of-bounds write flaw in the LINEMODE SLC suboption handler of GNU InetUtils telnetd. Exploitation occurs during the initial Telnet handshake on port 23, before authentication, and requires only a single network connection. No credentials or user interaction are required.

    Show sources

Information Snippets