CVE-2026-28372 | GNU inetutils up to 2.7 telnetd CREDENTIALS_DIRECTORY inclusion of functionality from untrusted control sphere (Nessus ID 300509 / WID-SEC-2026-0550)
A vulnerability, which was classified as critical, has been found in GNU inetutils up to 2.7. The impacted element is an unknown function of the component telnetd. Performing a manipulation of the argument CREDENTIALS_DIRECTORY results in inclusion of functionality from untrusted control sphere.
This vulnerability is cataloged as CVE-2026-28372. The attack must be initiated from a local position. There is no exploit available.