{"id":"CVE-2026-28372","details":"telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.","modified":"2026-08-12T03:51:24.703650562Z","published":"2026-02-27T05:28:17.383Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28372.json","unresolved_ranges":[{"extracted_events":[{"last_affected":"2.7"}],"source":"AFFECTED_FIELD"},{"source":"DESCRIPTION","extracted_events":[{"fixed":"2.7"}]}],"cna_assigner":"mitre","cwe_ids":["CWE-829"]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/02/27/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/03/06/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/03/06/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/03/07/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/03/07/2"},{"type":"WEB","url":"https://git.hadrons.org/cgit/debian/pkgs/inetutils.git/commit/?id=3953943d8296310485f98963883a798545ab9a6c"},{"type":"WEB","url":"https://lists.gnu.org/archive/html/bug-inetutils/2026-02/msg00000.html"},{"type":"WEB","url":"https://lists.gnu.org/archive/html/bug-inetutils/2026-02/msg00012.html"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/02/24/1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28372.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28372"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.hadrons.org/cgit/debian/pkgs/inetutils.git","events":[{"introduced":"0"},{"fixed":"3953943d8296310485f98963883a798545ab9a6c"}],"database_specific":{"source":"REFERENCES"}}],"versions":["2.7-2","2.6-3","2.7-1","2.6-4","2.6-2","2.6-1","2.5-6","2.5-5","2.5-4","2.5-3","2.5-2","2.5-1","2.4-3","2.4-2","2.4-1","2.3-6","2.0-1","2.3-5","2.3-4","2.3-3","2.3-2","2.3-1","2.2-2","2.2-1","2.1-2","2.1-1","1.9.4.91-1","1.9.4.90-1","1.9.4-13","1.9.4-12","1.9.4-11","1.9.4-10","1.9.4-9","1.9.4-8","1.9.4-7","1.9.4-6","1.9.4-5","1.9.4-4","1.9.4-3","1.9.4-2","1.9.4-1","1.9.3-2","1.9.3-1","1.9.2.39.3a460-3","1.9.2.39.3a460-2","1.9.2.39.3a460-1","1.9.2-1","1.9.1.363-bbc1-1","1.9.1.306-0a482-1","1.9.1.282-e8541-1","1.9-2","1.9-1","1.8-6","1.8-5","1.8-4","1.8-3","1.8-2","1.8-1","1.6-3","1.6-1","1.6-2","1.5.dfsg.1-5","1.5.dfsg.1-6","1.5.dfsg.1-7","1.5.dfsg.1-8","1.5.dfsg.1-9","1.5.dfsg.1-3","1.5.dfsg.1-4","1.4.3+20060719-3","1.5.dfsg.1-1","1.5.dfsg.1-2","1.4.3+20060719-2","1.4.3+20060719-1","1.4.3+20051212-4","1.4.3+20051212-1","1.4.3+20051212-2","1.4.3+20051212-3","1.4.2+20040207-5","1.4.2+20040207-6","1.4.2+20040207-4","1.4.2+20040207-3","1.4.2+20040207-1","1.4.2+20040207-2","1.4.2+20030703-7","1.4.2+20030703-1","1.4.2+20030703-8","1.4.2+20031022-1","20030701-1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28372.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}