CVE-2026-26068

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is accepted during check-in and later interpolated into tmux shell command strings executed via /bin/sh -c. This enables command injection and remote code execution on the operator host. This vulnerability is fixed in 3.21.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jm33-m0:emp3r0r:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-12 22:16

Updated : 2026-02-25 15:47


NVD link : CVE-2026-26068

Mitre link : CVE-2026-26068

CVE.ORG link : CVE-2026-26068


JSON object : View

Products Affected

jm33-m0

  • emp3r0r
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')