Command Injection Flaw in emp3r0r C2 by Linux Users for Linux Environments
CVE-2026-26068

9.3CRITICAL

Key Information:

Vendor

Jm33-m0

Status
Vendor
CVE Published:
12 February 2026

What is CVE-2026-26068?

A command injection vulnerability exists in emp3r0r, a command-and-control tool designed for Linux environments, which allows an attacker to execute arbitrary commands on the operator host. Prior to version 3.21.1, the software accepted untrusted agent metadata during check-in, including Transport and Hostname, which were then interpolated into tmux shell command strings. This flaw exposes the system to unauthorized code execution, requiring immediate attention and upgrade to version 3.21.1 or later to mitigate the risk.

Affected Version(s)

emp3r0r < 3.21.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.