Command Injection Flaw in emp3r0r C2 by Linux Users for Linux Environments
CVE-2026-26068
9.3CRITICAL
What is CVE-2026-26068?
A command injection vulnerability exists in emp3r0r, a command-and-control tool designed for Linux environments, which allows an attacker to execute arbitrary commands on the operator host. Prior to version 3.21.1, the software accepted untrusted agent metadata during check-in, including Transport and Hostname, which were then interpolated into tmux shell command strings. This flaw exposes the system to unauthorized code execution, requiring immediate attention and upgrade to version 3.21.1 or later to mitigate the risk.
Affected Version(s)
emp3r0r < 3.21.1
